PowerShellãšã»ãã¥ãªãã£ç£æ»
ããã©ãããããžã®ãæšæ¶ïŒ PowerShellã䜿çšããWindowsã·ã¹ãã ã®ã·ã¹ãã 管çã®ã«ãŒãã³ã«ãŒãã³ã容æã«ããæ¹æ³ãå ±æããããšæããŸãã
ããæŽããæ¥ãç§ã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãšããŠã¿ãŒããã«ãµãŒããŒã䜿çšãããŠãŒã¶ãŒã®ã¢ã¯ãã£ããã£ãæ¯æ¥ç£èŠããã¿ã¹ã¯ã«çŽé¢ããŸããã Windowsã®ç®¡çããŒã«ã®äžéšã§ãããã€ãã³ããã¥ãŒã¢ãŒãã¯ããµãŒããŒã®ç¶æ³ãç£èŠããã®ã«æã䟿å©ãªæ¹æ³ã§ã¯ãªããšèšã£ãŠãèªåã®æèŠã ãã§ãªãè¡šæãããšæããŸãã ã¯ããé¢å¿ã®ããã€ãã³ãã®ã¿ãé€å€ãããã£ã«ã¿ãŒããããŸããããã®æ å ±ã®è¡šç€ºåœ¢åŒãå€æŽãã䟿å©ãªæ¹æ³ã¯ãããŸããã ãã®çµæãPowerShellã䜿çšããŠã»ãã¥ãªãã£ãã°ã€ãã³ãã解æãããšããã¢ã€ãã¢ãçãŸããŸããã
ã€ãã³ãã®ãªã¹ããååŸããã«ã¯ãGet-EventLogã³ãã³ããå¿ èŠã§ãããã®ãã©ã¡ãŒã¿ãŒã®1ã€ã¯ãã°ã®ååã§ããã®å Žåã¯ã»ãã¥ãªãã£ã§ãã
ãã®ã³ãã³ãã¯ãã°å šäœã®å 容ã衚瀺ããŸãããããã¯åºæ¬çã«ç§ã«ã¯é©ããŠããŸããã ãããããã¹ãŠãããã»ã©æªãã¯ãããŸãããã¹ã¯ãªãŒã³ã·ã§ããã«è¡šç€ºãããã®ã¯ããã¹ãã ãã§ãªãããªããžã§ã¯ãã§ãããPowerShellã®ãã¬ãŒã ã¯ãŒã¯å ã§å¿ èŠãªãã¹ãŠã®ããããã£ãèšå®ã§ããŸãã ãããã®ãªããžã§ã¯ãã®ããããã£ãååŸãããšãGet-Memberã³ãã³ãã¬ãããèš±å¯ãããŸãã
Get-EventLog security | Get-Member
å®è¡ãã
Get-EventLog security | Get-Member
Get-EventLog security | Get-Member
ã§ã¯ãGet-EventLogã«ãã£ãŠè¡šç€ºããããã¹ãŠã®ãªããžã§ã¯ãã®ããããã£ã®ãªã¹ããååŸããŸãã
ããããã£ã®ãªã¹ãããããã°ãGet-EventLogã®çµæãæäœã§ããŸãã ããšãã°ãä»æ¥ã®ãã¹ãŠã®ã€ãã³ãã®äžèŠ§ãååŸããã«ã¯ãGet-EventLogã³ãã³ãã¬ããã®ãã©ã¡ãŒã¿ãŒãã€ãŸã
-after
ãã©ã¡ãŒã¿ãŒã䜿çšããã®ãæãç°¡åãªæ¹æ³ã§ãã ãã©ã¡ãŒã¿ã®å®å šãªãªã¹ãã¯ã ããã«ãããŸã ã ãã®çµæã
Get-EventLog security -after (Get-date -hour 0 -minute 0 -second 0)
ååŸããŸããGet-Dateã³ãã³ãã¬ããã¯çŸåšã®æ¥ä»ãšæå»ã衚瀺ããŸãããhourãminuteãsecondãã©ã¡ãŒã¿ãŒã¯æåããã®æéåºåãæå®ããŸãä»æ¥ã ãã®çµæãä»æ¥çºçããã€ãã³ãã®ãªã¹ããååŸããŸãã ãã§ã«åªããŠããŸãããããã§ãããã§ã¯ãããŸããã
RPDãããã³ã«ã䜿çšããŠãµãŒããŒã«ãã°ã€ã³ãããã¹ãŠã®ãŠãŒã¶ãŒã®ãªã¹ããååŸããå¿ èŠããããããEventIDãšEntryTypeã®å€ã調ã¹ãããšã«ãªããŸããã 次ã«ããããã®å€ã®å®å šãªãªã¹ãã¯æäŸããŸããã
EventIDå€
åãã°ã€ã³ã€ãã³ãã¯ãç¹å®ã®ãã°ã€ã³ã¿ã€ãã«ãã£ãŠè£å®ãããŸãããã®ãªã¹ãã以äžã«ãªã¹ãããŸãã
- 528-ã³ã³ãã¥ãŒã¿ãŒãžã®ãŠãŒã¶ãŒãã°ã€ã³ã«æåããŸããã
- 529-ãã°ã€ã³å€±æã ç¡å¹ãªãŠãŒã¶ãŒåãŸãã¯ãã¹ã¯ãŒãã
- 530-ãã°ã€ã³ã®å€±æã æå¹ãªæéééå€ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã§ãã°ã€ã³ããããšããŸããã
- 531-ãã°ã€ã³å€±æã ç¡å¹ãªãŠãŒã¶ãŒã¢ã«ãŠã³ãã䜿çšããŠãã°ã€ã³ããããšããŠããŸãã
- 532-ãã°ã€ã³å€±æã å€ããŠãŒã¶ãŒã¢ã«ãŠã³ãã䜿çšããŠãã°ã€ã³ããããšããŸããã
- 533-ãã°ã€ã³ã®å€±æã ãã®ã³ã³ãã¥ãŒã¿ãŒãžã®ãã°ãªã³ãèš±å¯ãããŠããªããŠãŒã¶ãŒã«ãã°ãªã³ããããšããŸããã
- 534-ãã°ã€ã³å€±æã äžæ£ãªãã°ã€ã³ã¿ã€ãã§ãã°ã€ã³ãè©Šã¿ãŸããã
- 535-ãã°ã€ã³å€±æã æå®ãããã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãã®æå¹æéãåããŠããŸãã
- 536-ãã°ã€ã³ã®å€±æã Net LogonãµãŒãã¹ã¯ç¡å¹ã«ãªã£ãŠããŸãã
- 537-ãã°ã€ã³å€±æã ä»ã®çç±ã§ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ã«å€±æããŸããïŒå Žåã«ãã£ãŠã¯ãã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãæåŠããçç±ãäžæãªå ŽåããããŸãïŒã
- 538-ãŠãŒã¶ãŒã®ãã°ã¢ãŠãããã»ã¹ãå®äºããŸããã
- 539-ãã°ã€ã³å€±æã ãã°ã€ã³è©Šè¡äžããŠãŒã¶ãŒã¢ã«ãŠã³ãã¯ããã¯ãããŸãã
- 540-ãããã¯ãŒã¯ãžã®ãŠãŒã¶ãŒãã°ã€ã³ã«æåããŸããã
- 541 âããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒãšç»é²ããããã¢IDïŒä¿¡é Œã§ããã¢ãœã·ãšãŒã·ã§ã³ã確ç«ããïŒãšã®éã®åºæ¬çãªIKEèªèšŒã¢ãŒããå®äºããããé«éã¢ãŒããããŒã¿ãã£ãã«ã確ç«ããŸããã
- 542-ããŒã¿ãã£ãã«ã¯ç¡å¹ã§ãã
- 543-ã¡ã€ã³ã¢ãŒããç¡å¹ã«ãªã£ãŠããŸãïŒãã®çç±ã¯ãä¿¡é Œã§ããæ¥ç¶ïŒããã©ã«ãã¯8æéïŒãããªã·ãŒã®å€æŽããŸãã¯ãã¢ã®çµäºã®æéãå¶éããæéééã®çµäºãããããŸããïŒã
- 544-ããŒãããŒãæå¹ãªèšŒææžãæäŸããªãã£ããã眲åãèªèšŒãããŠããªããšããäºå®ã«ããåºæ¬èªèšŒã¢ãŒãã®å€±æã
- 545-Kerberosãšã©ãŒãŸãã¯ç¡å¹ãªãã¹ã¯ãŒããåå ã§ããã©ã€ããªèªèšŒã¢ãŒãã倱æããŸããã
- 546-ããŒãããŒããã®åãå ¥ããããªããªãã¡ãŒãåå ã§ãä¿¡é Œã§ããIKEæ¥ç¶ãäœæã§ããªãã ç¡å¹ãªããŒã¿ãå«ããã±ãããåä¿¡ããŠââããŸãã
- 547-IKEæ¥ç¶ç¢ºç«æé äžã®å€±æã
- 548-ãã°ã€ã³ã®å€±æã ä¿¡é Œããããã¡ã€ã³ããåä¿¡ããä¿¡é Œæ§èå¥åïŒSIDïŒã¯ãã¯ã©ã€ã¢ã³ãã®ãã¡ã€ã³ã¢ã«ãŠã³ãã®SIDãšäžèŽããŸããã
- 549-ãã°ã€ã³å€±æã ä¿¡é ŒãããŠããªãåå空éã«é¢é£ä»ããããŠãããã¹ãŠã®SIDã¯ããã©ã¬ã¹ãèªèšŒäžã«é€å€ãããŸããã
- 550-ãµãŒãã¹ã«å¯Ÿããæ»æã®å¯èœæ§ã瀺ãéç¥ã¡ãã»ãŒãžã
- 551-ãŠãŒã¶ãŒããã°ã¢ãŠãããã»ã¹ãéå§ããŸããã
- 552-ãŠãŒã¶ãŒã¯ã以åã¯å¥ã®ãŠãŒã¶ãŒãšããŠãã°ã€ã³ããŠããã«ãããããããæ£ããè³æ Œæ å ±ã䜿çšããŠã³ã³ãã¥ãŒã¿ãŒã«æ£åžžã«ãã°ãªã³ããŸããã
- 682-ãŠãŒã¶ãŒã¯ãåæãããã¿ãŒããã«ãµãŒããŒã»ãã·ã§ã³ã«åæ¥ç¶ãããŸãã
- 683-ãŠãŒã¶ãŒã¯ãã°ã¢ãŠãããã«ã¿ãŒããã«ãµãŒããŒã»ãã·ã§ã³ããåæãããŸãïŒãã®ã€ãã³ãã¯ããŠãŒã¶ãŒããããã¯ãŒã¯çµç±ã§ã¿ãŒããã«ãµãŒããŒã»ãã·ã§ã³ã«æ¥ç¶ãããšãã«çæãããŸããã¿ãŒããã«ãµãŒããŒã«è¡šç€ºãããŸãïŒã
EntryTypeå€
- 2-ã€ã³ã¿ã©ã¯ãã£ãã ãŠãŒã¶ãŒãã³ã³ãã¥ãŒã¿ãŒã«æ£åžžã«ãã°ã€ã³ããŸããã
- 3-ãããã¯ãŒã¯ã ãŠãŒã¶ãŒãŸãã¯ã³ã³ãã¥ãŒã¿ãŒããããã¯ãŒã¯çµç±ã§ã³ã³ãã¥ãŒã¿ãŒã«ãã°ãªã³ããŸããã
- 4-ãããã ãšã³ããªã®ãã±ããã¿ã€ãã¯ããã±ãããµãŒããŒã«ãã£ãŠäœ¿çšãããŸãããã±ãããµãŒããŒã§ã¯ããŠãŒã¶ãŒã«ä»£ãã£ãŠããã»ã¹ãå®è¡ãããŸããããŠãŒã¶ãŒã®çŽæ¥ã®ä»å ¥ã¯å¿ èŠãããŸããã
- 5-ãµãŒãã¹ã ãµãŒãã¹ã¯ãµãŒãã¹ã³ã³ãããŒã«ãããŒãžã£ãŒã«ãã£ãŠéå§ãããŸãã
- 7-ããã¯è§£é€ã ãã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ããã¯è§£é€ãããŠããŸãã
- 8-NetworkCleartextã ãŠãŒã¶ãŒããããã¯ãŒã¯çµç±ã§ã³ã³ãã¥ãŒã¿ãŒã«ãã°ãªã³ããŸããã ãŠãŒã¶ãŒãã¹ã¯ãŒãã¯ãæªåæã®åœ¢åŒã§èªèšŒãã±ããã«æž¡ãããŸããã çµ±åèªèšŒã¯ãããã·ã¥ãããã¢ã«ãŠã³ãããã¹ãŠãããã¯ãŒã¯ã«éä¿¡ããåã«ããã¯ããŸãã è³æ Œæ å ±ã¯ãã¯ãªã¢ããã¹ãã§ãããã¯ãŒã¯çµç±ã§éä¿¡ãããŸããã
- 9-NewCredentialsã 蚪åè ã¯çŸåšã®ããŒã¯ã³ãè€è£œããçºä¿¡æ¥ç¶çšã®æ°ããã¢ã«ãŠã³ããæå®ããŸããã æ°ãããã°ã€ã³ã»ãã·ã§ã³ã¯åãããŒã«ã«IDãæã¡ãŸããããããã¯ãŒã¯æ¥ç¶ã«ç°ãªãã¢ã«ãŠã³ãã䜿çšããŸãã
- 10-RemoteInteractiveã ãŠãŒã¶ãŒãã¿ãŒããã«ãµãŒãã¹ãŸãã¯ãªã¢ãŒããã¹ã¯ãããã䜿çšããŠãã®ã³ã³ãã¥ãŒã¿ãŒã«ãªã¢ãŒãã§ãã°ãªã³ããŸããã
- 11-CachedInteractiveã ãŠãŒã¶ãŒãã³ã³ãã¥ãŒã¿ãŒã«ããŒã«ã«ã«ä¿åããããããã¯ãŒã¯è³æ Œæ å ±ã§ãã®ã³ã³ãã¥ãŒã¿ãŒã«ãã°ãªã³ããŸããã ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ãè³æ Œæ å ±ã®ç¢ºèªã«ã¯äœ¿çšãããŸããã§ããã
ãã®æ å ±ã¯äž»ã«ãã®ãœãŒã¹ããååŸãããŸã ã ååŸããæ å ±ãããRDPãä»ããã³ã³ãã¥ãŒã¿ãŒãžã®å ¥åã«å¯Ÿå¿ããEventID = 528ããã³EntryType = 10ã®ã€ãã³ããå¿ èŠã§ãããšçµè«ä»ããããšãã§ããŸãã ããŒã ãå°ãå€æŽããŸãããã
Get-EventLog security -message "* :?10*" -after (Get-date -hour 0 -minute 0 -second 0) | ?{$_.eventid -eq 528 }
-message
ãã©ã¡ãŒã¿ãŒã¯ãã€ãã³ãã®ã¡ãã»ãŒãžã
-message
åæ ããŸãããã®ã¡ãã»ãŒãžã«ã¯ã "Entry type"ïŒ2003幎ã®ãã·ã¢èªããŒãžã§ã³ãããããã "Input Type"ïŒãå«ãŸããŸãã
ã³ãã³ãã¬ããã®ãã©ã¡ãŒã¿ãŒã«Get_EventLog
-EventID
ãèŠã€ãããªãã£ãããããªããžã§ã¯ãããããã£ã®ããããã£ã䜿çšããå¿ èŠããããŸããã
$_
ã¯ãæåã«è¡šç€ºããããªããžã§ã¯ãèªäœãæå³ããŸã
-eq
ã¯ãå€ãçããããšãæå³ããŸãããã®å Žåã528
å®è¡ã®çµæã¯æ¬¡ã®ããã«ãªããŸãã
äžè¬çã«ãå¿ èŠãªãã®ã¯ãããŸãããééã£ãæ å ±ã®ã¿ã衚瀺ãããŸãã ä¿®æ£ããŸãã ãªããžã§ã¯ãã®3ã€ã®ãã©ã¡ãŒã¿ãŒã¯ãç§ã«ãšã£ãŠéèŠã§ãããããã¯ãæéããŠãŒã¶ãŒåãIPã¢ãã¬ã¹ã§ãã å°æ¥ããªããžã§ã¯ããäœæããèå³ã®ããããŒã¿ãå ¥åããŠãã ããã ã¹ã¯ãªãããtest.ps1ããäœæããŸããã ããŒã å šäœãå ¥åããã®ã«åé¡ããããŸãã
$Events = Get-EventLog security -message "* :?10*" -after (get-date -hour 0 -minute 0 -second 0) | ?{$_.eventid -eq 528 }
$Data = New-Object System.Management.Automation.PSObject
$Data | Add-Member NoteProperty Time ($null)
$Data | Add-Member NoteProperty UserName ($null)
$Data | Add-Member NoteProperty Address ($null)
$Events | %{
$Data.time = $_.TimeGenerated
$message = $_.message.split("`n") | %{$_.trimstart()} | %{$_.trimend()}
$Data.UserName = ($message | ?{$_ -like ":*"} | %{$_ -replace "^.+:."} )
$Data.Address = ($message | ?{$_ -like " :*"} | %{$_ -replace "^.+:."})
$data
}
ãã®ã³ãŒãã詳ããèŠãŠã¿ãŸãããã
$Events = Get-EventLog security -message "* :?10*" -after (get-date -hour 0 -minute 0 -second 0) | ?{$_.eventid -eq 528 }
$Events = Get-EventLog security -message "* :?10*" -after (get-date -hour 0 -minute 0 -second 0) | ?{$_.eventid -eq 528 }
-ã€ãã³ããéžæããçµæãå€æ°ã«
$Events = Get-EventLog security -message "* :?10*" -after (get-date -hour 0 -minute 0 -second 0) | ?{$_.eventid -eq 528 }
ããŸããããã«ãããå°æ¥çã«ã€ãã³ããåŠçããã®ã«äŸ¿å©ã§ãã
次ã«ãæéããŠãŒã¶ãŒåãã¢ãã¬ã¹ã®3ã€ã®å€ãå«ãå°æ¥ã®ããŒãã«ã®ããã³ãã¬ãŒãããäœæããŸãã
$Data = New-Object System.Management.Automation.PSObject
$Data | Add-Member NoteProperty Time ($null)
$Data | Add-Member NoteProperty UserName ($null)
$Data | Add-Member NoteProperty Address ($null
$Data = New-Object System.Management.Automation.PSObject
$Data | Add-Member NoteProperty Time ($null)
$Data | Add-Member NoteProperty UserName ($null)
$Data | Add-Member NoteProperty Address ($null
ïŒ
$Events | %{}
$Events | %{}
-éžæçµæã«å«ãŸããåãªããžã§ã¯ããééããŸã
$Data.time = $_.TimeGenerated
æéã
$Data.time = $_.TimeGenerated
$message = $_.message.split("`n") | %{$_.trimstart()} | %{$_.trimend()}
$message = $_.message.split("`n") | %{$_.trimstart()} | %{$_.trimend()}
ã
$Data.UserName = ($message | ?{$_ -like ":*"} | %{$_ -replace "^.+:."} )
$Data.Address = ($message | ?{$_ -like " :*"} | %{$_ -replace "^.+:."})
$Data.UserName = ($message | ?{$_ -like ":*"} | %{$_ -replace "^.+:."} )
$Data.Address = ($message | ?{$_ -like " :*"} | %{$_ -replace "^.+:."})
次ã«ãæ°ãã圢æãããé åã§ãè¡ "ãŠãŒã¶ãŒïŒãããã³ããœãŒã¹ãããã¯ãŒã¯ã¢ãã¬ã¹ïŒããããã³-replaceã¯ãããã®æ£èŠè¡šçŸãããã«åé€ããæ å ±èªäœãæ®ããŸãã
ã³ãã³ã
.\test.ps1
ã䜿çšããŠã¹ã¯ãªãããå®è¡ããŸãã ïŒã芧ã®ãšãããPSã¹ã¯ãªãããå®è¡ããã«ã¯ãçŸåšã®äœæ¥ãã©ã«ããŒã«ããå Žåã§ããã¹ãæå®ããå¿ èŠããããŸãïŒïŒ
ã¹ã¯ãªãããéå§ãããªãã£ãå ŽåãPoShãã¹ã¯ãªãããå®è¡ããããã«æ§æãããŠããªãå¯èœæ§ããããŸãã
Set-ExecutionPolicy RemoteSignet
ãŸãã
ããªãè¯ãããã«èŠããŸãããã¹ã¯ãªãããæ¹åã§ãããšæããŸãã 䟿å®äžããã©ã¡ãŒã¿ãèšå®ããIPã¢ãã¬ã¹ãã¹ã¯ã䜿çšããŠè²ä»ãã®ç·ã匷調衚瀺ããæ©èœãè¿œå ããŸãã
param ($key1,$val1,$val2,$val3,$val4,$val5,$val6)
if ($val1 -eq $null) {$val1=0};
$mydate = Get-date -hour 0 -minute 0 -second 0;
if ($key1 -eq "year") { $mydate = (Get-date -hour 0 -minute 0 -second 0 -day 1 -month 1); $mydate = $mydate.addyears(-$val1); };
if ($key1 -eq "month") { $mydate = (Get-date -hour 0 -minute 0 -second 0 -day 1); $mydate = $mydate.addmonths(-$val1); };
if ($key1 -eq "day") { $mydate = $mydate.adddays(-$val1) };
if ($key1 -eq "date") { $mydate = (Get-date -hour 0 -minute 0 -second 0 -day $val1 -month $val2 -year $val3); }; #
if ($val4 -eq $null) {$Events = Get-EventLog security -message "* :?10*" -after ($mydate) | ?{$_.eventid -eq 528 }}
if ($val4 -ne $null) {$Events = Get-EventLog security -message "* :?10*" -after ($mydate) -before (get-date -hour 0 -minute 0 -second 0 -day $val4 -month $val5 -year $val6) | ?{$_.eventid -eq 528 }}
$Data = New-Object System.Management.Automation.PSObject
$Data | Add-Member NoteProperty Time ($null)
$Data | Add-Member NoteProperty UserName ($null)
$Data | Add-Member NoteProperty Address ($null)
$Events | %{
$Data.time = $_.TimeGenerated
$message = $_.message.split("`n") | %{$_.trimstart()} | %{$_.trimend()}
$Data.UserName = ($message | ?{$_ -like ":*"} | %{$_ -replace "^.+:."} )
$Data.Address = ($message | ?{$_ -like " :*"} | %{$_ -replace "^.+:."})
$textcolor = $host.ui.rawui.foregroundcolor
$host.ui.rawui.foregroundcolor = "red"
if ($data.address -like "192.168.0*") {$host.ui.rawui.foregroundcolor = "DarkGreen"}
if ($data.address -like "10.*") {$host.ui.rawui.foregroundcolor = "yellow"}
$data
$host.ui.rawui.foregroundcolor = $textcolor
}
param ($key1,$val1,$val2,$val3,$val4,$val5,$val6)
-ã¹ã¯ãªããã«æž¡ããããã©ã¡ãŒã¿ãŒãå®çŸ©ããŸãã
if ($key1 -eq "day") { $mydate = $mydate.adddays(-$val1) };;
転éããããã©ã¡ãŒã¿ãŒãããŒã«æºæ ããŠãããã©ããã確èªããããŒãäžèŽããå Žåã¯ãæå®ããããã©ã¡ãŒã¿ãŒã«åŸã£ãŠæ¥ä»ã調æŽããŸãã ãã®å Žåããæ¥ãããŒããã©ã¡ãŒã¿ãŒãšããŠæž¡ãããåŒæ°ã䜿çšããŠç¹å®ã®æ¥æ°åã«æ¥ä»ãå€æããŸãã ã€ãŸã ãã°ã¯äžå®ã®æ¥æ°è¡šç€ºãããæ®ãã®æ¡ä»¶ã¯é¡æšã«ããã1ãæãš1幎æºããããŸãã ãæ¥ä»ãããŒãæå®ãããŠããå Žåãã¹ããŒã¹ã§ç€ºãããç¹å®ã®æ¥ä»ãéå§ç¹ãšããŠäœ¿çšãããŸãïŒäŸïŒã01 05 2011ãïŒãã¹ããŒã¹ã§å¥ã®æ¥ä»ãæå®ãããšããããã®æ¥ä»ã«ç€ºãããç¹å®ã®æéã衚瀺ãããŸãã æ å ±ãã«ã©ãŒã§åºåããã«ã¯ããã©ã¡ãŒã¿-backgroundcolorããã³-foregroundcolorãæã€Write-Hostã³ãã³ãã¬ããã䜿çšããããšãåœåèšç»ãããŠããŸããããæçµçã«ã¯ãªããžã§ã¯ãã®åºåã«éŠŽæã¿ããªãããããããæŸæ£ããªããã°ãªããŸããã§ããã
ããããããããããã«ãå éšããŒã«ã«ãããã¯ãŒã¯ã®è¡šç€ºãç·è²ãå€éšã®é»è²ããã®ä»ã®ãªãã¿ã®ãªãã¢ãã¬ã¹ããã¹ãŠèµ€ã«ããŸããã
ãããŠã
{$_.eventid -eq 529 }
ãèšå®ãããšãäžæ£ãªãã¹ã¯ãŒãã䜿çšãããã¹ãŠã®ãã°ã€ã³è©Šè¡ã«ãªããŸãã
ãªã¹ãã¯ããªãé·ãã1æ¥ã«2ã3åããã¡ã€ã¢ãŠã©ãŒã«äžã®ãã®ãããªæªäººããã§ãã¯ããŠãããã¯ãããšäŸ¿å©ã§ãã
ãã®çµæãæå°éã®å€æŽã§ã¹ã¯ãªããã調æŽããŠãã€ãã³ããã°ã«å«ãŸããæ å ±ãç°¡åã«è¡šç€ºã§ããŸãã