{"id":1795,"date":"2024-05-09T10:52:03","date_gmt":"2024-05-09T02:52:03","guid":{"rendered":"https:\/\/www.vmsvr.com\/wordpress\/?p=1795"},"modified":"2024-05-15T08:52:26","modified_gmt":"2024-05-15T00:52:26","slug":"powershell%e5%8f%91%e9%80%81windows%e6%97%a5%e5%bf%97%e5%88%b0%e6%95%b0%e6%8d%ae%e5%ba%93","status":"publish","type":"post","link":"https:\/\/www.vmsvr.com\/wordpress\/technology\/2024\/05\/09\/1795.html","title":{"rendered":"PowerShell\u53d1\u9001Windows\u65e5\u5fd7\u5230\u6570\u636e\u5e93"},"content":{"rendered":"<p>\u6700\u8fd1\u5728\u5c1d\u8bd5\u5c06Windows\u4e8b\u4ef6\u65e5\u5fd7\u53d1\u9001\u5230Sql Server\u6216\u8005Mysql\uff0c\u7f51\u4e0a\u7ffb\u4e86\u4e00\u5708\u53d1\u73b0\u8fd8\u662f<span class='wp_keywordlink_affiliate'><a href=\"https:\/\/www.vmsvr.com\/wordpress\/tag\/powershell\" title=\"View all posts in PowerShell\" target=\"_blank\">PowerShell<\/a><\/span>\u65b9\u4fbf\u76f4\u8fdeSql Server\u3002<\/p>\n<p>\u5148\u521b\u5efa\u6570\u636e\u5e93\u811a\u672c<br \/>\n<code><br \/>\nCREATE TABLE [dbo].[SecurityLog] (<br \/>\n[ID] bigint IDENTITY(1,1) NOT NULL,<br \/>\n[LogIndex] bigint NULL,<br \/>\n[LogTime] nvarchar(50) COLLATE Chinese_PRC_CI_AS NULL,<br \/>\n[LogEntryType] nvarchar(255) COLLATE Chinese_PRC_CI_AS NULL,<br \/>\n[LogInstanceId] int NULL,<br \/>\n[LogSource] nvarchar(1000) COLLATE Chinese_PRC_CI_AS NULL,<br \/>\n[LogMessage] nvarchar(4000) COLLATE Chinese_PRC_CI_AS NULL,<br \/>\n[Hostname] nvarchar(255) COLLATE Chinese_PRC_CI_AS NULL,<br \/>\n[HostIP] nvarchar(50) COLLATE Chinese_PRC_CI_AS NULL,<br \/>\n[addtime] nvarchar(50) COLLATE Chinese_PRC_CI_AS DEFAULT CONVERT([varchar](19),getdate(),(120)) NULL<br \/>\n)<br \/>\nGO<br \/>\n<\/code><br \/>\n<!--more--><\/p>\n<p>\u4ee5\u4e0b\u4e3a<span class='wp_keywordlink_affiliate'><a href=\"https:\/\/www.vmsvr.com\/wordpress\/tag\/powershell\" title=\"View all posts in PowerShell\" target=\"_blank\">PowerShell<\/a><\/span>\u5c06Windows<span class='wp_keywordlink_affiliate'><a href=\"https:\/\/www.vmsvr.com\/wordpress\/tag\/%e6%97%a5%e5%bf%97%e5%86%99%e5%85%a5%e6%95%b0%e6%8d%ae%e5%ba%93\" title=\"View all posts in \u65e5\u5fd7\u5199\u5165\u6570\u636e\u5e93\" target=\"_blank\">\u65e5\u5fd7\u5199\u5165\u6570\u636e\u5e93<\/a><\/span>\u811a\u672c<\/p>\n<p><code>#\u914d\u7f6e\u4fe1\u606f<br \/>\n$Database   = 'EventLog'<br \/>\n$Server     = 'localhost'<br \/>\n$UserName   = 'eventlog'<br \/>\n$Password   = 'Security2024'<br \/>\n$Hostname   =($env:COMPUTERNAME).Trim(\"`t`n`r\").replace(\" \",\"\")<br \/>\n$HostIP     =((ipconfig|select-string \"IPv4\"|out-string).Split(\":\")[-1]).Trim(\"`t`n`r\").replace(\" \",\"\")<br \/>\n<\/code><\/p>\n<p><code>#\u521b\u5efa\u8fde\u63a5\u5bf9\u8c61<br \/>\n$SqlConn = New-Object System.Data.SqlClient.SqlConnection<\/code><\/p>\n<p><code>#\u4f7f\u7528\u8d26\u53f7\u8fde\u63a5MSSQL<br \/>\n$SqlConn.ConnectionString = \"Data Source=$Server;Initial Catalog=$Database;user id=$UserName;pwd=$Password\"<\/code><\/p>\n<p><code>#\u6216\u8005\u4ee5 windows \u8ba4\u8bc1\u8fde\u63a5 MSSQL<br \/>\n#$SqlConn.ConnectionString = \"Data Source=$Server;Initial Catalog=$Database;Integrated Security=SSPI;\"<\/code><\/p>\n<p><code>#\u6253\u5f00\u6570\u636e\u5e93\u8fde\u63a5<br \/>\n$SqlConn.open()<\/code><\/p>\n<p><code>#\u83b7\u53d6\u5b89\u5168\u65e5\u5fd7<br \/>\n#\u83b7\u53d6\u524d\u4e00\u5929\u65e5\u5fd7<br \/>\n$items=Get-EventLog -LogName \"Security\" -after ((Get-Date).AddDays(-1).ToString(\"MM-dd-yyyy\")+\" 00:00:00\")<\/code><\/p>\n<p><code>##\u904d\u5386\u65e5\u5fd7<br \/>\nforeach($item in $items)<br \/>\n{<\/code><\/p>\n<p><code>$LogIndex=$item.Index.tostring()<br \/>\n$LogTime=$item.TimeWritten.tostring(\"yyyy-MM-dd HH:mm:ss\").replace(\"'\",\"\")<br \/>\n$LogEntryType=$item.EntryType.tostring()<br \/>\n$LogInstanceId=$item.InstanceID<br \/>\n$LogSource=$item.Source.tostring().replace(\"'\",\"\")<br \/>\n$LogMessage=$item.Message.replace(\"'\",\"\")<\/code><\/p>\n<p><code>#\u83b7\u53d6\u8be6\u7ec6\u65e5\u5fd7<br \/>\n#$itemdetail=Get-EventLog -LogName \"Security\" -Index $LogIndex | Select-Object -Property *<\/code><\/p>\n<p><code>#\u5c06<span class='wp_keywordlink_affiliate'><a href=\"https:\/\/www.vmsvr.com\/wordpress\/tag\/%e6%97%a5%e5%bf%97%e5%86%99%e5%85%a5%e6%95%b0%e6%8d%ae%e5%ba%93\" title=\"View all posts in \u65e5\u5fd7\u5199\u5165\u6570\u636e\u5e93\" target=\"_blank\">\u65e5\u5fd7\u5199\u5165\u6570\u636e\u5e93<\/a><\/span><br \/>\n$SqlCmd = New-Object System.Data.SqlClient.SqlCommand<br \/>\n$SqlCmd.connection = $SqlConn<br \/>\n$SqlCmd.commandtext = \"INSERT INTO [dbo].[SecurityLog]([LogIndex],[LogTime],[LogEntryType],[LogInstanceId],[LogSource],[LogMessage],[Hostname],[HostIP])VALUES($LogIndex,'$LogTime','$LogEntryType','$LogInstanceId','$LogSource','$LogMessage','$Hostname','$HostIP');\"<br \/>\n$SqlCmd.executenonquery()<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>#\u5173\u95ed\u6570\u636e\u5e93\u8fde\u63a5\uff0c\u9000\u51fa\u811a\u672c<br \/>\n$SqlConn.close()<br \/>\nExit<\/code><\/p>\n<p>\u4ee5\u4e0a\u811a\u672c\u53ea\u662f\u5c06<span class='wp_keywordlink_affiliate'><a href=\"https:\/\/www.vmsvr.com\/wordpress\/tag\/windows%e6%97%a5%e5%bf%97\" title=\"View all posts in Windows\u65e5\u5fd7\" target=\"_blank\">Windows\u65e5\u5fd7<\/a><\/span>\u5199\u5165\u5230\u6570\u636e\u5e93\u91cc\uff0c\u5982\u679c\u9700\u8981\u5177\u4f53\u62c6\u5206\u5206\u6790\u65e5\u5fd7\uff0c\u5c31\u9700\u8981\u81ea\u5df1\u989d\u5916\u589e\u52a0\u811a\u672c\u6216\u8005\u7a0b\u5e8f\u3002<br \/>\n\u811a\u672c\u4fdd\u5b58\u5b8c\u6bd5\uff0c\u53ef\u4ee5\u518d\u505a\u4e00\u4e2a\u4efb\u52a1\u8ba1\u5212\uff0c\u6bcf\u5929\u665a\u4e0a\u5b9a\u65f6\u6267\u884c<span class='wp_keywordlink_affiliate'><a href=\"https:\/\/www.vmsvr.com\/wordpress\/tag\/powershell\" title=\"View all posts in PowerShell\" target=\"_blank\">PowerShell<\/a><\/span>\u811a\u672c\uff0c\u4f46\u662f\u6709\u4e00\u70b9\uff0cPowerShell\u811a\u672c\u8bbe\u7f6e\u4efb\u52a1\u8ba1\u5212\u6ca1\u6709dos bat\u811a\u672c\u8bbe\u7f6e\u65b9\u4fbf\u3002<br \/>\n\u4ee5\u4e0b\u4e3a\u91cd\u70b9\uff1a<br \/>\n\u5728\u64cd\u4f5c\u7684\u9009\u9879\u5361\u4e2d\u9700\u8981\u9009\u62e9\u7a0b\u5e8f\u6216\u811a\u672c\u4f4d\u7f6e\uff1aC:\\Windows\\System32\\WindowsPowerShell\\v1.0\\PowerShell.exe<br \/>\n\u6dfb\u52a0\u53c2\u6570\uff08\u53ef\u9009\uff09\uff1a<code>-NonInteractive \"D:\\Shell\\logtodb.ps1\"<\/code><br \/>\n\u5177\u4f53\u6b65\u9aa4\u53ef\u4ee5\u53c2\u8003\u7f51\u4e0a\u6559\u7a0b\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6700\u8fd1\u5728\u5c1d\u8bd5\u5c06Windows\u4e8b\u4ef6\u65e5\u5fd7\u53d1\u9001\u5230Sql Server\u6216\u8005Mysql\uff0c\u7f51\u4e0a &hellip; <a href=\"https:\/\/www.vmsvr.com\/wordpress\/technology\/2024\/05\/09\/1795.html\">\u7ee7\u7eed\u9605\u8bfb <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[139,620],"tags":[1027,1025,1026],"class_list":["post-1795","post","type-post","status-publish","format-standard","hentry","category-technology","category-os","tag-powershell","tag-windows","tag-1026"],"views":352,"_links":{"self":[{"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/posts\/1795","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/comments?post=1795"}],"version-history":[{"count":0,"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/posts\/1795\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/media?parent=1795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/categories?post=1795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vmsvr.com\/wordpress\/wp-json\/wp\/v2\/tags?post=1795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}