回复 5# 522235677 | $evt=Get-WinEvent -LogName Security -FilterXPath "Event[System[EventID=4625 and TimeCreated[timediff(@SystemTime)<=600000]]]" -MaxEvents 1 -ErrorAction SilentlyContinue | | if($null -ne $evt){ | | $ip=$evt.Properties[19].Value | | curl.exe http://test.com?ip=$ip | | }COPY |
|