求助完善PowerShell脚本提取VPN日志指定字段并导出CSV
完善PowerShell脚本提取VPN日志指定字段并导出CSV
我有一个存储VPN客户端连接信息的TXT文件,需要提取time、remip、srcip、msg、user、status字段并导出至CSV文件。目前编写的PowerShell脚本仅能提取time和remip字段,请求协助完善脚本以获取全部所需字段。
日志文件示例
2022-07-17 17:08:12 Local7.Info 10.10.50.14 date=2022-07-17 time=17:08:12 devname="FortiGate-201F" devid="FG201FT920901378" logid="0101039424" type="event" subtype="vpn" level="information" vd="root" eventtime=1658059692736060755 tz="+0500" logdesc="SSL VPN tunnel up" action="tunnel-up" tunneltype="ssl-web" tunnelid=850652314 remip=10.10.50.182 user="abc" group="N/A" dst_host="N/A" reason="login successfully" msg="SSL tunnel established" 2022-07-17 17:08:13 Local7.Notice 10.10.50.14 date=2022-07-17 time=17:08:13 devname="FortiGate-201F" devid="FG201FT920901378" logid="0102043039" type="event" subtype="user" level="notice" vd="root" eventtime=1658059693829159815 tz="+0500" logdesc="Authentication logon" srcip="10.212.134.200" user="abc" authserver="N/A" action="auth-logon" status="logon" msg="User abc added to auth logon" 2022-07-17 17:09:04 Local7.Notice 10.10.50.14 date=2022-07-17 time=17:09:04 devname="FortiGate-201F" devid="FG201FT920901378" logid="0102043040" type="event" subtype="user" level="notice" vd="root" eventtime=1658059744761943019 tz="+0500" logdesc="Authentication logout" srcip="10.212.134.200" user="abc" authserver="N/A" action="auth-logout" status="logout" msg="User abc removed from auth logon"
现有PowerShell代码
$input_path = 'C:\Users\sajjad\Documents\test\sil\*.txt' $output_file = 'C:\Users\sajjad\Documents\test\sil\VpnLogInLogOff.csv' $regex = '\b(time|remip|user|msg)\b=([^\s ]+)' #regular expression is providing time and remote ip. Select-String $input_path -AllMatches -Pattern $regex | ForEach-Object { $obj = New-Object pscustomobject }
完善后的脚本
要提取全部所需字段,需要调整正则表达式以覆盖所有目标字段,同时处理字段值包含空格(比如带引号的msg内容)的情况,还要处理部分日志行缺失某些字段的场景。以下是完善后的脚本:
$input_path = 'C:\Users\sajjad\Documents\test\sil\*.txt' $output_file = 'C:\Users\sajjad\Documents\test\sil\VpnLogInLogOff.csv' # 正则表达式匹配所有目标字段,支持带引号的字段值 $regex = '\b(time|remip|srcip|msg|user|status)\b=(?:"([^"]+)"|([^\s]+))' # 初始化结果数组 $results = @() Select-String $input_path -AllMatches -Pattern $regex | ForEach-Object { $obj = [PSCustomObject]@{ time = $null remip = $null srcip = $null msg = $null user = $null status = $null } # 遍历所有匹配项,填充对应字段 for ($i = 0; $i -lt $_.Matches.Count; $i++) { $match = $_.Matches[$i] $fieldName = $match.Groups[1].Value # 优先取带引号的匹配值,没有则取纯文本值 $fieldValue = if ($match.Groups[2].Success) { $match.Groups[2].Value } else { $match.Groups[3].Value } $obj.$fieldName = $fieldValue } $results += $obj } # 导出到CSV $results | Export-Csv -Path $output_file -NoTypeInformation -Encoding UTF8
关键说明
- 正则表达式调整:新增
srcip和status字段,同时修改匹配逻辑,支持提取带双引号的字段值(比如msg的内容),避免空格截断。 - 字段初始化:提前定义所有目标字段并设为
null,确保即使日志行缺失某些字段,CSV中仍会保留对应列。 - 匹配值处理:判断字段值是带引号还是纯文本,正确提取内容。
- CSV导出:使用
Export-Csv时添加-NoTypeInformation避免生成类型信息行,指定UTF8编码保证兼容性。
内容的提问来源于stack exchange,提问作者Sajjad Muslim
相关产品推荐
相关产品推荐

