OCS Inventory是否支持远程WMI?如何替代客户端VBS脚本实现?
Alright, let's tackle this: replacing OCS Inventory's client-side VBS script with remote WMI to pull system serialization info. I've implemented this for several enterprise environments to avoid deploying scripts to every endpoint, so here's a practical, step-by-step guide:
OCS Inventory's VBS client essentially calls Windows WMI and system APIs under the hood to collect hardware/serialization data. Remote WMI lets you skip deploying the script entirely by directly querying those same data sources from a central machine.
- WMI Service Enabled: The target machine must have the
winmgmtservice running (it's enabled by default on Windows, but double-check if it's been disabled). - Firewall Access: Ensure the target's firewall allows WMI traffic (default ports: 135 for RPC, plus dynamic ports; you can lock this down to a fixed port range via group policy if needed).
- Admin Permissions: You need local administrator credentials for each target machine—WMI requires this to read hardware/system serialization data.
- Tools: Use PowerShell (recommended for flexibility) or the built-in
WMICcommand-line tool (no extra installs needed).
1. Map OCS Serialization Data to WMI Classes
First, identify which WMI classes hold the data OCS collects. Here's the key mapping:
- BIOS Serial Number:
Win32_BIOS→SerialNumberproperty - Motherboard Serial Number:
Win32_BaseBoard→SerialNumberproperty - Physical Hard Drive Serial:
Win32_DiskDrive→SerialNumberproperty (filter for fixed disks to exclude virtual drives) - CPU ID:
Win32_Processor→ProcessorIdproperty - System UUID:
Win32_ComputerSystemProduct→UUIDproperty
2. PowerShell Remote WMI Queries (Recommended)
PowerShell is more flexible for batch operations and error handling. Below are working examples:
Single Machine Query
# Replace with your target machine's hostname/IP $targetPC = "DESKTOP-ABC123" $adminCreds = Get-Credential -Message "Enter admin credentials for $targetPC" # Fetch BIOS details Get-WmiObject -Class Win32_BIOS -ComputerName $targetPC -Credential $adminCreds | Select-Object SerialNumber, Manufacturer, SMBIOSBIOSVersion # Fetch motherboard serial Get-WmiObject -Class Win32_BaseBoard -ComputerName $targetPC -Credential $adminCreds | Select-Object SerialNumber, Product # Fetch physical disk serial (filter out virtual drives) Get-WmiObject -Class Win32_DiskDrive -ComputerName $targetPC -Credential $adminCreds | Where-Object {$_.MediaType -eq "Fixed hard disk media"} | Select-Object DeviceID, SerialNumber, Model # Fetch CPU ID Get-WmiObject -Class Win32_Processor -ComputerName $targetPC -Credential $adminCreds | Select-Object ProcessorId, Name # Fetch system UUID Get-WmiObject -Class Win32_ComputerSystemProduct -ComputerName $targetPC -Credential $adminCreds | Select-Object UUID
Batch Machine Query (Export to CSV)
This script pulls data from a list of machines and saves results to a CSV (perfect for replacing OCS's inventory export):
# Load target machines from a text file (one hostname/IP per line) $targetList = Get-Content "C:\temp\enterprise-pcs.txt" $adminCreds = Get-Credential -Message "Enter shared admin credentials for target PCs" # Loop through each machine and collect data $inventoryResults = foreach ($pc in $targetList) { try { # Fetch core hardware data $bios = Get-WmiObject -Class Win32_BIOS -ComputerName $pc -Credential $adminCreds -ErrorAction Stop $motherboard = Get-WmiObject -Class Win32_BaseBoard -ComputerName $pc -Credential $adminCreds -ErrorAction Stop $primaryDisk = Get-WmiObject -Class Win32_DiskDrive -ComputerName $pc -Credential $adminCreds -ErrorAction Stop | Where-Object {$_.MediaType -eq "Fixed hard disk media"} | Select-Object -First 1 $cpu = Get-WmiObject -Class Win32_Processor -ComputerName $pc -Credential $adminCreds -ErrorAction Stop $systemUUID = Get-WmiObject -Class Win32_ComputerSystemProduct -ComputerName $pc -Credential $adminCreds -ErrorAction Stop # Format results into a structured object [PSCustomObject]@{ ComputerName = $pc BIOS_Serial = $bios.SerialNumber Motherboard_Serial = $motherboard.SerialNumber Primary_Disk_Serial = $primaryDisk.SerialNumber CPU_ID = $cpu.ProcessorId System_UUID = $systemUUID.UUID Collection_Time = Get-Date -Format "yyyy-MM-dd HH:mm:ss" } } catch { # Handle errors (e.g., unreachable machine, permission denied) [PSCustomObject]@{ ComputerName = $pc BIOS_Serial = "ERROR: $($_.Exception.Message)" Motherboard_Serial = "" Primary_Disk_Serial = "" CPU_ID = "" System_UUID = "" Collection_Time = Get-Date -Format "yyyy-MM-dd HH:mm:ss" } } } # Export results to CSV for easy analysis $inventoryResults | Export-Csv -Path "C:\temp\ocs-replacement-inventory.csv" -NoTypeInformation
3. WMIC Command-Line Alternative (For Legacy Systems)
If you need to use a command-line tool instead of PowerShell, WMIC works for quick queries:
:: Replace with your target machine and admin credentials set TARGET_PC=DESKTOP-ABC123 set ADMIN_USER=LOCAL_ADMIN set ADMIN_PASS=YourStrongPassword123 :: Query BIOS serial wmic /node:%TARGET_PC% /user:%ADMIN_USER% /password:%ADMIN_PASS% bios get serialnumber :: Query motherboard serial wmic /node:%TARGET_PC% /user:%ADMIN_USER% /password:%ADMIN_PASS% baseboard get serialnumber :: Query physical disk serial wmic /node:%TARGET_PC% /user:%ADMIN_USER% /password:%ADMIN_PASS% diskdrive where mediatype="Fixed hard disk media" get serialnumber, deviceid
- Empty Serial Numbers: Some OEMs don't populate certain fields (e.g., motherboard serial) in WMI. If you need this data, you'll have to check the physical machine's sticker.
- Permission Issues: If you get "Access Denied" errors, confirm your account has local admin rights on the target machine, and that UAC isn't blocking remote WMI access.
- Batch Performance: For large fleets, add a throttle limit to PowerShell (use
Invoke-Command -ThrottleLimit 10) to avoid overwhelming your network. - Extend to Full OCS Functionality: To replicate all OCS inventory features, add queries for software (
Win32_Product), network config (Win32_NetworkAdapterConfiguration), and user accounts (Win32_UserAccount).
内容的提问来源于stack exchange,提问作者MUY Belgium

