You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为多路径NTFS权限查询PowerShell脚本添加Try-Catch异常捕获

为NTFS权限采集脚本添加异常捕获功能

需求说明

现有PowerShell脚本用于从App-Path.txt(每行一个路径)读取目标路径,遍历Servers.txt中的服务器,采集文件夹及子文件夹的NTFS权限并输出到CSV。需要补充异常捕获逻辑,将路径不存在、权限不足等异常信息写入同一份输出CSV。

修改后完整代码

# 读取配置文件
$FolderPaths = Get-Content .\App-Path.txt
$Servers = Get-Content .\Servers.txt
$Output = @()

ForEach ($Server in $Servers) {
    Write-Host "正在从服务器 $Server 采集NTFS权限"
    # 遍历每个目标路径,转换为UNC路径适配远程服务器
    ForEach ($Path in $FolderPaths) {
        $uncPath = "\\$Server\$($Path.Replace(':$', '$'))" # 处理本地盘符路径转为UNC,如C:\Folder转为\\Server\C$\Folder
        Write-Host "正在处理路径: $uncPath"

        # 尝试获取当前路径下的所有子文件夹(含自身)
        Try {
            $FolderContent = Get-ChildItem -Path $uncPath -Recurse -Force -Directory -ErrorAction Stop
            # 遍历每个文件夹采集权限
            ForEach ($Folder in $FolderContent) {
                Try {
                    $ACL = Get-Acl -Path $Folder.FullName -ErrorAction Stop
                    # 遍历每条权限记录
                    ForEach ($Access in $ACL.Access) {
                        # 过滤无效权限数值
                        if ($Access.FileSystemRights -notin (-1610612736, 268435456)) {
                            $Properties = [ordered]@{
                                '服务器'     = $Server
                                '文件夹路径' = $Folder.FullName
                                '用户/组'    = $Access.IdentityReference
                                '权限'       = $Access.FileSystemRights
                                '是否继承'   = $Access.IsInherited
                                '异常信息'   = $null
                            }
                            $Output += New-Object -TypeName PSObject -Property $Properties
                        }
                    }
                }
                Catch {
                    # 捕获获取ACL时的异常
                    $errorMsg = $_.Exception.Message
                    $Properties = [ordered]@{
                        '服务器'     = $Server
                        '文件夹路径' = $Folder.FullName
                        '用户/组'    = $null
                        '权限'       = $null
                        '是否继承'   = $null
                        '异常信息'   = "获取权限失败: $errorMsg"
                    }
                    $Output += New-Object -TypeName PSObject -Property $Properties
                }
            }
        }
        Catch {
            # 捕获路径不存在或无法访问的异常
            $errorMsg = $_.Exception.Message
            $Properties = [ordered]@{
                '服务器'     = $Server
                '文件夹路径' = $uncPath
                '用户/组'    = $null
                '权限'       = $null
                '是否继承'   = $null
                '异常信息'   = "路径访问失败: $errorMsg"
            }
            $Output += New-Object -TypeName PSObject -Property $Properties
        }
    }
}

# 输出最终CSV
$Output | Export-Csv -Path .\NTFS-权限结果.csv -NoTypeInformation -Encoding UTF8

关键修改说明

  • 路径适配远程服务器:将本地路径转换为UNC格式(\\服务器名\盘符$\路径),确保跨服务器路径访问有效
  • 双层Try-Catch结构:
    • 外层捕获Get-ChildItem的异常:处理路径不存在、无法访问文件夹的情况
    • 内层捕获Get-Acl的异常:处理权限不足无法读取ACL的情况
  • 异常信息写入CSV:新增异常信息字段,将错误详情写入同一份输出,便于后续排查
  • 权限数值过滤:将原脚本末尾的过滤逻辑整合到权限采集环节,避免重复读写CSV
  • 指定UTF8编码:解决CSV中文乱码问题

内容的提问来源于stack exchange,提问作者Puneet Tiwari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 15:10:16