You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助完善PowerShell脚本提取VPN日志指定字段并导出CSV

完善PowerShell脚本提取VPN日志指定字段并导出CSV

我有一个存储VPN客户端连接信息的TXT文件,需要提取time、remip、srcip、msg、user、status字段并导出至CSV文件。目前编写的PowerShell脚本仅能提取time和remip字段,请求协助完善脚本以获取全部所需字段。

日志文件示例

2022-07-17 17:08:12    Local7.Info 10.10.50.14 date=2022-07-17 time=17:08:12 devname="FortiGate-201F" devid="FG201FT920901378" logid="0101039424" type="event" subtype="vpn" level="information" vd="root" eventtime=1658059692736060755 tz="+0500" logdesc="SSL VPN tunnel up" action="tunnel-up" tunneltype="ssl-web" tunnelid=850652314 remip=10.10.50.182 user="abc" group="N/A" dst_host="N/A" reason="login successfully" msg="SSL tunnel established"

2022-07-17 17:08:13 Local7.Notice   10.10.50.14 date=2022-07-17 time=17:08:13 devname="FortiGate-201F" devid="FG201FT920901378" logid="0102043039" type="event" subtype="user" level="notice" vd="root" eventtime=1658059693829159815 tz="+0500" logdesc="Authentication logon" srcip="10.212.134.200" user="abc" authserver="N/A" action="auth-logon" status="logon" msg="User abc added to auth logon"

2022-07-17 17:09:04 Local7.Notice   10.10.50.14 date=2022-07-17 time=17:09:04 devname="FortiGate-201F" devid="FG201FT920901378" logid="0102043040" type="event" subtype="user" level="notice" vd="root" eventtime=1658059744761943019 tz="+0500" logdesc="Authentication logout" srcip="10.212.134.200" user="abc" authserver="N/A" action="auth-logout" status="logout" msg="User abc removed from auth logon"

现有PowerShell代码

$input_path = 'C:\Users\sajjad\Documents\test\sil\*.txt'

$output_file = 'C:\Users\sajjad\Documents\test\sil\VpnLogInLogOff.csv'

$regex = '\b(time|remip|user|msg)\b=([^\s ]+)' #regular expression is providing time and remote ip. 

Select-String $input_path -AllMatches -Pattern $regex | ForEach-Object {

    $obj = New-Object pscustomobject

    
}

完善后的脚本

要提取全部所需字段,需要调整正则表达式以覆盖所有目标字段,同时处理字段值包含空格(比如带引号的msg内容)的情况,还要处理部分日志行缺失某些字段的场景。以下是完善后的脚本:

$input_path = 'C:\Users\sajjad\Documents\test\sil\*.txt'
$output_file = 'C:\Users\sajjad\Documents\test\sil\VpnLogInLogOff.csv'

# 正则表达式匹配所有目标字段,支持带引号的字段值
$regex = '\b(time|remip|srcip|msg|user|status)\b=(?:"([^"]+)"|([^\s]+))'

# 初始化结果数组
$results = @()

Select-String $input_path -AllMatches -Pattern $regex | ForEach-Object {
    $obj = [PSCustomObject]@{
        time   = $null
        remip  = $null
        srcip  = $null
        msg    = $null
        user   = $null
        status = $null
    }

    # 遍历所有匹配项,填充对应字段
    for ($i = 0; $i -lt $_.Matches.Count; $i++) {
        $match = $_.Matches[$i]
        $fieldName = $match.Groups[1].Value
        # 优先取带引号的匹配值,没有则取纯文本值
        $fieldValue = if ($match.Groups[2].Success) { $match.Groups[2].Value } else { $match.Groups[3].Value }
        $obj.$fieldName = $fieldValue
    }

    $results += $obj
}

# 导出到CSV
$results | Export-Csv -Path $output_file -NoTypeInformation -Encoding UTF8

关键说明

  • 正则表达式调整:新增srcip和status字段,同时修改匹配逻辑,支持提取带双引号的字段值(比如msg的内容),避免空格截断。
  • 字段初始化:提前定义所有目标字段并设为null,确保即使日志行缺失某些字段,CSV中仍会保留对应列。
  • 匹配值处理:判断字段值是带引号还是纯文本,正确提取内容。
  • CSV导出:使用Export-Csv时添加-NoTypeInformation避免生成类型信息行,指定UTF8编码保证兼容性。

内容的提问来源于stack exchange,提问作者Sajjad Muslim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 23:36:23