如何在PowerShell中为WSUS客户端列表添加AD描述字段
解决PowerShell中WSUS客户端统计列表添加AD计算机描述字段的问题
问题概述
已实现通过PowerShell获取WSUS客户端的更新统计(包含所需更新、已安装更新等),现在需要在统计列表中添加对应AD计算机的Description字段,但无法实现关联匹配。
现有基础代码(已实现WSUS统计)
[Reflection.Assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration") $wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer('XXX',$true,XXXX) $computerscope = New-Object Microsoft.UpdateServices.Administration.ComputerTargetScope $updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope $wsus.GetSummariesPerComputerTarget($updatescope,$computerscope) | Format-Table @{L='ComputerTarget';E={($wsus.GetComputerTarget([guid]$_.ComputerTargetId)).FullDomainName}}, @{L='NeededCount';E={($_.DownloadedCount + $_.NotInstalledCount)}},DownloadedCount,NotApplicableCount,NotInstalledCount,InstalledCount,FailedCount -Autosize
未完成的尝试代码(需添加AD描述字段)
[Reflection.Assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration") $wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer('XXX',$true,XXXX) $computerscope = New-Object Microsoft.UpdateServices.Administration.ComputerTargetScope $updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope $adusers = Get-ADComputer -Filter * -SearchBase "OU=XXX,DC=XXX,DC=XXX" -Properties "Description","DNSHostName" $wsus.GetSummariesPerComputerTarget($updatescope,$computerscope) | Format-Table @{L='ComputerTarget';E={($wsus.GetComputerTarget([guid]$_.ComputerTargetId)).FullDomainName}}, @{L='Username';E={???}}, @{L='NeededCount';E={($_.DownloadedCount + $_.NotInstalledCount)}},DownloadedCount,NotApplicableCount,NotInstalledCount,InstalledCount,FailedCount -Autosize
解决方案
核心思路是将AD计算机数据转换为哈希表,以计算机的域名(或DNS主机名)作为键,快速匹配WSUS统计中的计算机,从而取出对应的Description字段:
- 先将
Get-ADComputer获取到的数据构建成哈希表,键为DNSHostName(与WSUS返回的FullDomainName格式一致),值为Description; - 在
Format-Table的自定义列中,通过当前WSUS计算机的FullDomainName去哈希表中查找对应的描述。
修改后的完整代码
[Reflection.Assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration") $wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer('XXX',$true,XXXX) $computerscope = New-Object Microsoft.UpdateServices.Administration.ComputerTargetScope $updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope # 获取AD计算机数据并构建哈希表,用于快速匹配 $adComputers = Get-ADComputer -Filter * -SearchBase "OU=XXX,DC=XXX,DC=XXX" -Properties "Description","DNSHostName" $adDescHash = @{} foreach ($computer in $adComputers) { # 确保DNSHostName不为空时才添加到哈希表 if ($computer.DNSHostName) { $adDescHash[$computer.DNSHostName] = $computer.Description } } $wsus.GetSummariesPerComputerTarget($updatescope,$computerscope) | Format-Table @{L='ComputerTarget';E={ $computer = $wsus.GetComputerTarget([guid]$_.ComputerTargetId) # 存储FullDomainName,避免重复调用 $computer.FullDomainName }}, @{L='AD描述';E={ $computerName = $wsus.GetComputerTarget([guid]$_.ComputerTargetId).FullDomainName # 从哈希表中匹配对应的描述,无匹配则返回空字符串 $adDescHash[$computerName] ?? '' }}, @{L='NeededCount';E={($_.DownloadedCount + $_.NotInstalledCount)}}, DownloadedCount,NotApplicableCount,NotInstalledCount,InstalledCount,FailedCount -Autosize
补充说明
- 哈希表的构建是为了避免在每条WSUS数据中都遍历一次AD列表,大幅提升处理效率;
- 使用
?? ''确保当WSUS中的计算机在AD中无匹配时,该列显示空值而非报错; - 若WSUS返回的
FullDomainName与AD的DNSHostName格式不一致(比如大小写差异),可统一转换为小写后再匹配,例如:$adDescHash[$computer.DNSHostName.ToLower()] = $computer.Description和$adDescHash[$computerName.ToLower()] ?? ''
内容的提问来源于stack exchange,提问作者Trikrux
相关产品推荐
相关产品推荐

