You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在PowerShell中为WSUS客户端列表添加AD描述字段

解决PowerShell中WSUS客户端统计列表添加AD计算机描述字段的问题

问题概述

已实现通过PowerShell获取WSUS客户端的更新统计(包含所需更新、已安装更新等),现在需要在统计列表中添加对应AD计算机的Description字段,但无法实现关联匹配。

现有基础代码(已实现WSUS统计)

[Reflection.Assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration")
$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer('XXX',$true,XXXX)
$computerscope = New-Object Microsoft.UpdateServices.Administration.ComputerTargetScope
$updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope
$wsus.GetSummariesPerComputerTarget($updatescope,$computerscope) |
        Format-Table @{L='ComputerTarget';E={($wsus.GetComputerTarget([guid]$_.ComputerTargetId)).FullDomainName}},
@{L='NeededCount';E={($_.DownloadedCount + $_.NotInstalledCount)}},DownloadedCount,NotApplicableCount,NotInstalledCount,InstalledCount,FailedCount -Autosize

未完成的尝试代码(需添加AD描述字段)

[Reflection.Assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration")
$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer('XXX',$true,XXXX)
$computerscope = New-Object Microsoft.UpdateServices.Administration.ComputerTargetScope
$updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope
$adusers = Get-ADComputer -Filter * -SearchBase "OU=XXX,DC=XXX,DC=XXX" -Properties "Description","DNSHostName"
$wsus.GetSummariesPerComputerTarget($updatescope,$computerscope) |
        Format-Table @{L='ComputerTarget';E={($wsus.GetComputerTarget([guid]$_.ComputerTargetId)).FullDomainName}},
@{L='Username';E={???}},
@{L='NeededCount';E={($_.DownloadedCount + $_.NotInstalledCount)}},DownloadedCount,NotApplicableCount,NotInstalledCount,InstalledCount,FailedCount -Autosize

解决方案

核心思路是将AD计算机数据转换为哈希表,以计算机的域名(或DNS主机名)作为键,快速匹配WSUS统计中的计算机,从而取出对应的Description字段:

  • 先将Get-ADComputer获取到的数据构建成哈希表,键为DNSHostName(与WSUS返回的FullDomainName格式一致),值为Description;
  • 在Format-Table的自定义列中,通过当前WSUS计算机的FullDomainName去哈希表中查找对应的描述。

修改后的完整代码

[Reflection.Assembly]::LoadWithPartialName("Microsoft.UpdateServices.Administration")
$wsus = [Microsoft.UpdateServices.Administration.AdminProxy]::getUpdateServer('XXX',$true,XXXX)
$computerscope = New-Object Microsoft.UpdateServices.Administration.ComputerTargetScope
$updatescope = New-Object Microsoft.UpdateServices.Administration.UpdateScope

# 获取AD计算机数据并构建哈希表,用于快速匹配
$adComputers = Get-ADComputer -Filter * -SearchBase "OU=XXX,DC=XXX,DC=XXX" -Properties "Description","DNSHostName"
$adDescHash = @{}
foreach ($computer in $adComputers) {
    # 确保DNSHostName不为空时才添加到哈希表
    if ($computer.DNSHostName) {
        $adDescHash[$computer.DNSHostName] = $computer.Description
    }
}

$wsus.GetSummariesPerComputerTarget($updatescope,$computerscope) |
    Format-Table @{L='ComputerTarget';E={
        $computer = $wsus.GetComputerTarget([guid]$_.ComputerTargetId)
        # 存储FullDomainName,避免重复调用
        $computer.FullDomainName
    }},
    @{L='AD描述';E={
        $computerName = $wsus.GetComputerTarget([guid]$_.ComputerTargetId).FullDomainName
        # 从哈希表中匹配对应的描述,无匹配则返回空字符串
        $adDescHash[$computerName] ?? ''
    }},
    @{L='NeededCount';E={($_.DownloadedCount + $_.NotInstalledCount)}},
    DownloadedCount,NotApplicableCount,NotInstalledCount,InstalledCount,FailedCount -Autosize

补充说明

  • 哈希表的构建是为了避免在每条WSUS数据中都遍历一次AD列表,大幅提升处理效率;
  • 使用?? ''确保当WSUS中的计算机在AD中无匹配时,该列显示空值而非报错;
  • 若WSUS返回的FullDomainName与AD的DNSHostName格式不一致(比如大小写差异),可统一转换为小写后再匹配,例如:$adDescHash[$computer.DNSHostName.ToLower()] = $computer.Description 和 $adDescHash[$computerName.ToLower()] ?? ''

内容的提问来源于stack exchange,提问作者Trikrux

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 18:45:47