PowerShell Pipes and Filtering

One of PowerShell's most powerful features is the "pipe" mechanism.

The pipe allows you to combine multiple commands like building blocks, with each step processing and passing objects. This not only makes scripts more concise, but also greatly improves the flexibility and efficiency of data processing.

This section will introduce the pipe's|basic principles, two filtering methods, object property extraction, and common combination techniques, helping you write more powerful and intelligent command-line operations.


1. What is a Pipe?

In PowerShell,the pipe symbol|(vertical bar) means passing the output of the previous command to the next command as input.

Unlike the text streams in traditional command lines, what is passed through the PowerShell pipe isobjects,which makes operations more precise and powerful.

Example: List running services and sort them

Get-Service | Where-Object {$_.Status -eq "Running"} | Sort-Object DisplayName

Explanation:

  1. Get-ServiceGet all service objects;
  2. Where-ObjectFilter out services with a status of Running;
  3. Sort-ObjectSort by service name.

2. Object Filtering: Where-Object

Basic Syntax

Where-Object { 条件表达式 }

In{}Inside, use$_to represent each object in the current pipe.

Example 1: Filter processes with memory usage over 500MB

Get-Process | Where-Object { $_.WorkingSet -gt 500MB }

Example 2: Filter services whose names start with "Win"

Get-Service | Where-Object { $_.Name -like "Win*" }

3. Extracting Properties: Select-Object

Select-ObjectIt is used to extract the fields you care about from objects, often for concise output, redirecting to files, or building reports.

Example: List the names and statuses of all services

Get-Service | Select-Object Name, Status

You can also rename fields:

Get-Service | Select-Object @{Name="服务名"; Expression={$_.DisplayName}}, Status

4. Sorting Data: Sort-Object

Sort-ObjectIt is used to sort objects according to a specific property.

Example 1: Sort processes by memory usage in descending order

Get-Process | Sort-Object WorkingSet -Descending | Select-Object Name, WorkingSet -First 5

5. Output and Formatting: Format-Table, Out-File, etc.

Example: Display service information in table form

Get-Service | Format-Table -Property Name, Status, DisplayName

Output to a file:

Get-Service | Where-Object {$_.Status -eq "Running"} | 
    Select-Object Name, DisplayName |
    Out-File -FilePath "C:\RunningServices.txt"

6. Common Usage Combinations (Practical)

1. View all processes consuming CPU (sorted by CPU usage)

Get-Process | Where-Object { $_.CPU -gt 0 } | Sort-Object CPU -Descending

2. Find all services with "Time" in their names

Get-Service | Where-Object { $_.DisplayName -like "*Time*" }

3. Export hard disk information

Get-CimInstance Win32_LogicalDisk |
    Select-Object DeviceID, VolumeName, Size, FreeSpace |
    Export-Csv -Path "C:\diskinfo.csv" -NoTypeInformation

7. Where-Object Shorthand (PowerShell 3.0+)

PowerShell 3.0 and later versions support shorthand syntax:

Where-Object Name -like "*Win*"

Equivalent to:

Where-Object { $_.Name -like "*Win*" }

Beginners are advised to first become familiar with the standard syntax, and use the shorthand later to improve efficiency.


8. Overview of Common Pipeline Operation Commands

Command Function Description
Where-Object Filter objects conditionally
Select-Object Extract specified properties
Sort-Object Sort by property
Format-Table Format output as a table
Out-File Write output to a text file
Export-Csv Export data to a CSV file

9. Summary

  • PowerShell pipes are based onobject passing,which is more powerful than traditional text pipes
  • Where-Objectis the core tool for data filtering
  • Select-ObjectandSort-Objectcan flexibly extract, sort, and organize data
  • Combining multiple commands can accomplish complex data processing tasks and is the foundation of system automation

10. Practice Tasks

Task 1:Filter all services starting with "W" and sort them by name

Get-Service | Where-Object { $_.Name -like "W*" } | Sort-Object Name

Task 2:List the top 10 processes with the highest memory usage

Get-Process | Sort-Object WorkingSet -Descending | Select-Object Name, WorkingSet -First 10

Task 3:Export all local IPv4 addresses to a file

Get-NetIPAddress -AddressFamily IPv4 | Select-Object IPAddress | Out-File -FilePath "C:\ip_list.txt"
Other Extensions