Comments
-
This is a manifestation of the First Time Use Wizard (FTUW) trying to do to the client what you have already done manually. Do not use the FTUW to configure a client that is already configured.
-
Yes. If you will be defining Automation Server Routing Rules such that the Automation Server is serving defined systems exclusively and those systems will only use that Automation Server, then you want to remove it from the pool.
-
To get connected via WMI (to deploy an update; run detectnow; use Computer Explorer), requires a *credential* to be defined in the Credential Ring that has local administrator permissions on the target system. If this is what you did (in Security and User Management -> Credential Rings), then great, but creating a *user*…
-
but my server doesn't have a 'USERS' group in the permissions section. Is this a Domain Controller? All systems have a "Users" group, except Domain Controllers. If it's a DC, then you'll need to grant access to the "Domain Users" group. Do I need to add this on the WSUS/Patch Manager server, or shouldn't this group already…
-
Presumably this tool is developed in house. If all it does is change BIOS settings, and does nothing else to the target computer, then it is not a suitable target for being packaged for WSUS. At a minimum you need to modify the utility to "leave a trace behind". An appropriate option might be a registry value in…
-
It's not impossible to perform this task in the context of the WUA and PackageBoot; however, the requirements to achieve it are somewhat onerous, and you'd have to build a single self-contained script that can handle all of the necessary requirements of implementing the various copy events to howevermany %userprofile%…
-
Generally speaking, if Patch Manager is on a dedicated server, it will work fine with the local (installed by default) instance of SQL Server 2008R2 Express Edition. Exceptions to this would be driven by a large number of computers involved in WMI-based asset inventory collection, a notably large WSUS environment (e.g.…
-
Regarding the installation of content from the Dell catalogs. All Dell content is based on WMI queries into their own OpenManage WMI namespaces. You'll need to publish and deploy the Dell OpenManage Inventory Agent. Note, also, that there are separate inventory agent packages for clients and servers, and there are several…
-
Certain systems without Altaro Hyper-V Backup.exe report the patch as applicable. Is this because the file version is technically below 4.1.20.0, even though the file doesn't exist? Yes, because you're using a File Version rule which also returns TRUE if the file is non-existant. To specify an UPGRADE-ONLY scenario, you'll…
-
With respect to the impact of expired patches, your question (#1) makes great sense, Phil; however, the reasoning is the more fundamental limitation that the Server Cleanup Wizard does not touch any update that has an approval assigned. While I cannot disagree that it would be nice to have the SCW pay special attention to…
-
Is there a good way to be able to approve these patches but selectively miss this random group of machines. Yes, and I just posted a blog article in PatchZone yesterday that describes exactly how do to this. Using Multiple WSUS Target Groups
-
Whether you unpin it, or close it, you can recover the toolbar by mousing over the top center of the remote session window, which will redisplay the toolbar in the top center. Effectively it does "auto-hide" if you unpin it rather than close it, it "auto-hides" to the top center.
-
Greetings Doug. All files transferred via WSUS to the Windows Update Agent are held in an update-specific installation source folder under %windir%\SoftwareDistribution\Download. The actual CAB file is copied into the ~\Download folder and extracted from there. Generally speaking, if the installer allows for relative…
-
One thing I just discovered.... these URLs are incorrect. They must be IDENTICAL. Either you're using SSL, or you're not.
-
Client error 0x800b0109, covered in KB Article #3641. What's configured in the GPO is not near as relevant as what's actually APPLIED to the client. Assuming the certificate expiring August 2016 is the correct certificate, the logical conclusion here is that the GPO didn't actually get applied, and thus the option Allow…
-
Follow the provided instructions in the Package Download Assistant for the Skype v6.0.0.120 package, which says: This link will take you to the Skype for Windows download page. Choose the Skype Free - Download Skype button to save the SkypeSetup.exe file. Once downloaded, choose the Import Source button on the top left of…
-
There is a lot of information available about how to download, deploy, and report on patches and patch compliance but I don't see anyone discussing the discretionary parts of the process. Your observation is consistent with mine, and I think the reason for this is the very word you used: discretionary. When something is…
-
As you can see from the screen shot, the icon shows a green dot, but the % used shows it's critical. Does the status not reflect in the icon? I believe the key here is the purpose of the resource vs the additional information presented. The resource is "Database Disk I/O". The green indicator in the resource indicates that…
-
If you have installed an Automation Server in the DMZ and need to communicate directly with the clients in the DMZ, the configuration is exactly the same as it would be for an Automation Server and clients on the internal network: - File Sharing must be enabled to deploy the WMI Providers - Windows Management…
-
The first thing we need to determine is what your criteria for the "last 7 days" and "last 60 days" are. Are you interested in: * Release Date (by vendor) (All updates or just Approved Updates?) * Arrival Date (on WSUS) (All updates or just Approved Updates?) * Approval Date * Installation Date (and with respect to this…
-
This error "Verification of file signature failed for file:" when the file is successfully transferred to the ~\UpdateServicesPackages file share is typically caused because: * The WSUS Signing Certificate has not been created * The WSUS Signing Certificate has not been distributed to the Patch Manager server(s). Start by…
-
So, first let's clarify the reason for the two installers. BOTH installers are the Business version, and applying a Chrome update via PatchManager/WSUS to any system will convert that system from a User version to a Business version. You cannot, however, use the EXE package to upgrade a previously existing MSI-based…
-
It is not currently possible to daisy-chain or sequence tasks with Patch Manager, but I'm pretty certain that it's on the Feature Request list for some future release. However, it may be possible to achieve what you need to do by using the Automation Role's ability to throttle worker processes and threads per process. By…
-
The question I have is; does the command line honor the windows variable? Quite likely, not. The installation runs in the SYSTEM context when installed by the WUAgent, and as such has a very thinly defined environment. I would suggest hardcoding that pathname to a known, permanent location accessible to the SYSTEM account,…
-
There is not currently any data sharing between NPM and Patch Manager. The discovery and inventory tasks executed from Patch Manager operate as independent tasks, and store data in a separate data store.
-
Greetings Mark. It's not so much that Flash nor Java do not typically require a system or service restart, but the fact must be that they never will require a system or service restart -- in any conceivable scenario. The first thing to note in this point is that the Java packages in SolarWinds Patch Manager do potentially…
-
Greetings Heath. If you enable client reporting to the SUP as discussed in this blog article, you can then run a daily WSUS Inventory and use the Computer Update Status report to geneate this information. You can filter by one or more machines, export that filtered view to Excel, and then email the Excel report to the…
-
Everything appears to work fine but the publishing and approving of an update in Site B is very very slow. I suspect that some of the traffic is coming back across the WAN to the PAS in Site A. Quite likely! Be sure you've defined an Automation Server Routing Rule for the WSUS Server on Site B so that all traffic for that…
-
Greetings Alan. A couple of questions to get us started. Is this an evaluation installation or a full installation of Patch Manager? What version of Patch Manager are you using? Also relevant, what installer type are you using (MSI or EXE)? Finally, from the questions-to-ask list: Is this the SolarWinds provided instance…
-
Generally speaking, the "Could not establish trust relationship for the SSL/TLS secure channel" would be an expected response if the connection only supports HTTPS connections and you're trying to use an HTTP monitor. Use an HTTPS Monitor for those targets, and make sure that the SAM/NPM server has the required SSL/TLS…