Hi all,
We just got Solarwinds Patch Manager at our company and it was given to me to "Figure it out". My goal is to set Patch Manager up in such a way that we can use it to deploy all Windows Updates going forward and I'm wondering how you all use it and if you have any suggestions for the following scenario:
- We have upwards 15 domains that are in our initial list of domains that we are managing.
- These domains are spread across 2 datacenters in different parts of the world initially, but this is going to expand to upwards of 15 when this is done.
- Our initial server list is about 6000 and we are going to be expanding this to over 15000 when all is said and done.
- We have 2 maintenance windows per month, one dedicated to each datacenter. We are expected to get all the servers in each datacenter patched during that short 4 hour window. To make things more fun, one of the datacenters twice the size of the other one (So roughly 4000 and 2000)
- At any given time, one or more of our application environments may need to be excluded from patching.
- We don't know that we have everything in WSUS and past IT people did a terrible job of cleaning up Active Directory, so trying to figure out exactly what needs to be patched is a bit of a nightmare.
We tried this out with patch groups via AD rules, but it seems like the scheduled patching executes things in a linear fashion, so we didn't even get through all 2000 servers during our patch window. We broke them up into smaller groups of about 100 a piece and that seemed to work better, but it didn't give us the granularity we needed and the lack of being able to create subgroups within SWPM means we end up with a massive list of patch groups.
Any thoughts?