Remote Monitoring & Management Help

WSUS Check

Microsoft's Windows Server Update Services (WSUS) is a free patch management tool that enables system administrators to deploy Microsoft product updates across their organization from a centralized source, the WSUS server.

The WSUS server synchronizes with an update repository, either Microsoft Update or another WSUS server, to retrieve updates in accordance with the administrator specified product, product families and update types (i.e. Critical or Security Updates).

Update deployment can be setup in two ways, either the system administrator must approve all updates or WSUS can be configured to approve certain classes of update automatically.

Whichever method is chosen, once an update is selected it can be downloaded to the WSUS server and from there pushed out across the organization.

The WSUS Check queries the WSUS database for the last synchronization information and reports this back to the Dashboard, along with the number of critical updates that have not yet installed successfully on all computers. As such this Check is only available on the WSUS server.

Add

  1. Select the device in the north pane of the Dashboard
  2. Go to the Checks tab
  3. Click Add Check
  4. Choose Add DSC > WSUS Check
  5. Click Enable WSUS Check and configure the Alert when exceeding thresholds (Agent 7.1.2 onwards). Pre-Agent 7.1.2 simply Enable WSUS Check
  6. To run an Automated Task when the Check fails choose Assign a Task after creating the Check
  7. OK to save and apply
  8. Where Assign a Task after creating the Check is selected:
    1. Select the script
    2. Click Next to configure
  9. Enter the Command Line parameters (if required)
  10. Set a Script timeout in the range 1 - 3600 seconds (default 120 seconds)
  11. Click Finish to save and apply

Edit

  1. Select the device in the north pane of the Dashboard
  2. Go to the Checks tab
  3. Select the target WSUS Check
  4. From the Check drop-down
  5. Click Edit Check (also available from the Check's right-click menu)
  6. Configure the settings
  7. Click OK to save and apply

Delete

  1. Select the device in the north pane of the Dashboard
  2. Go to the Checks tab
  3. Select the target WSUS Check
  4. From the Check drop-down
  5. Click Delete Check (also available from the Check's right-click menu)
  6. Enter the password you have logged into the Dashboard under to confirm removal
  7. Click OK to delete

Settings

*Agent 7.1.2 onwards

Thresholds can be configured for each of the following:

  • Computers needing updates
  • Computers with update errors
  • Updates needed
  • Updates with errors
  • Computers not contacted for over 30 days

wsus2_agent

Pre-Agent 7.1.2

Does not contains a threshold setting and the Check is simply enabled and returns the synchronization status:

  • Last sync result
  • Last sync time
  • Sync Status
  • Computers with update errors
  • Computers not connected for over 30 days
  • Number of critical updates not yet installed

If the following three conditions are true the check passes, if any are false the check fails:

  • The last synchronization result must be 1 (Successful)
  • The number of computers with update errors must be 0
  • The number of updates with errors must be 0

clip0067

More Informaiton

The Agent retrieves all of the information from the main page of the WSUS console which can be displayed by clicking the link in the Extra/More Information section of the Dashboard that corresponds to the Check.

Depending on the version of WSUS installed, will contain the following information:

More Information section for WSUS v2.0 and More Information section for WSUS v3.0

wsus2_more_info wsus3_check_pane

WSUS from Small Business Server 2008

To allow the Agent to query WSUS on Small Business Server 2008 the account the Advanced Monitoring Agent service runs under must be a member of the WSUS Administrators.

This may be achieved via the Server Manager

  1. Roles
  2. Active Directory Domain
  3. Services
  4. Active Directory
  5. Active Directory users and computers
  6. Domain

And select either:

  1. Users
  2. WSUS Administrators
  3. Right-Click
  4. Properties
  5. Members
  6. Add
  7. Select Account

OR

  1. My Business
  2. Users
  3. SBS Users
  4. Select Account
  5. Right-Click
  6. Properties
  7. Member of
  8. Add
  9. Select WSUS Administrators