Jump to content

Recommended Posts

Posted

Hi folks,

 

Our WSUS is misbehaving - slow, sometimes comes up with the "reset server node" message when trying to open, times out when displaying it last synchronised etc.

 

I have used the Technet cleanup script (https://gallery.technet.microsoft.com/WSUS-cleanup-script-7e019537), which removed a few hundred updates, but it is getting stuck deleting 10 updates e.g. 850293, as follows:

 

Connecting to database SUSDB on MICROSOFT##WID
Declining expired updates
Declining superseded updates
Reading obsolete update list.
Found 10 updates that can be deleted.
Deleting update 850923 (1 of 10)
Error deleting update 850923:
Exception calling "ExecuteNonQuery" with "0" argument(s): "Execution Timeout Expired.  The timeout period elapsed prior
to completion of the operation or the server is not responding."
Re-opening database connection

 

Are there better cleanup scripts to run, or something else that can help with this issue?

 

Thanks

Posted

Where is the paid script?

 

Update Compliance presumably uses Azure? We still have local DCs. I have been looking to move over from a dedicated WSUS server to SCCM with WSUS, so this might accelerate it.

Posted

It runs on azure, but doesn't cost money. It's the only azure thing I use, local servers otherwise.

 

There's https://gallery.technet.microsoft.com/scriptcenter/Optimize-and-cleanup-of-eb9d8640 and https://gallery.technet.microsoft.com/scriptcenter/6f8cde49-5c52-4abd-9820-f1d270ddea61

 

The paid thing is

 

But seems like MS has abandoned WSUS, and now we have smaller updates and p2p lan sharing, I just killed it when it broke and switched. It tells me which computers are out of date, works when laptops stay at home, and saves me 500GB of storage.

  • Thanks 1
Posted

Um, MS haven’t abandoned WSUS. You’ve posted this a couple of times and I can’t see any evidence to back it up?

 

Also Update Compliance is not a replacement for WSUS, it monitors and reports on your update status but you still need to get the updates on the machine in the first place. How are you managing that?

  • Thanks 2
Posted
You can just use Windows Update for Business with Intune or without. If you want reporting you need intune I believe. WSUS isn't dead but it does need looking after like any server. Adding all products is bound to break it. There are numerous blog posts from those in the Configmgr community about tweaks you need to make to WSUS. Don't manage it via the mmc. Use powershell or Configmgr and use it as a SUP. Mine has been pretty stable on 2019 since I moved it from my Primary Site Server and gave it sql express for its DB. I try and clear out older updates and legacy products. Sometimes I think just go for WUfB but I don't think it's quite there. There were some announcements at Ignite that bring some more features which will be in public preview soon
  • Thanks 1
Posted

It's gone from bad to worse as the server seemed to become unstable, so I restored from Veeam and the server is now even more unstable - services aren't running, and can't be started. Oddly I had this exact same issue with a different 2012 R2 server a few weeks back. I tried to restore that from Veeam as well, same problem, and eventually had to rebuild it. It's almost as if servers are corrupting, but I'm not sure if the Veeam restore is at fault.

 

I'm trying a restore again from Veeam, from the oldest restore point, and will see how it goes. If the worst comes to the worst I'll have to rebuild it from scratch, and that will be the time to move WSUS over to SCCM, which I was partway through doing anyway. The frustrating bit is that our ESET server is also on the server, and I need the certificates from it to migrate... *fingers crossed*

Posted
Um, MS haven’t abandoned WSUS. You’ve posted this a couple of times and I can’t see any evidence to back it up?

 

Also Update Compliance is not a replacement for WSUS, it monitors and reports on your update status but you still need to get the updates on the machine in the first place. How are you managing that?

 

All those new features in WSUS in the past 10 years show there's 100s of programmers on the case. That time when you had to manually fix it to make Win 10 feature updates work.

 

WUfB and p2p

Posted
Since making the changes to the IIS application pool settings my WSUS servers have been reliable. Occasionally need to run the AdamJ cleanup script when I run out of space. Fine otherwise.
Posted
So after saying WSUS has been OK the last few months. Office 365 Proplus updates are playing up. Oh what joy!

Does WSUS serve O365 PP updates? I have this vague memory that they just don't exist as a product.

Posted
Does WSUS serve O365 PP updates? I have this vague memory that they just don't exist as a product.

Kind of... you need sccm to manage 365 updates via wsus.

Posted
When it's not broken. For the Monthly Channel it doesn't seem to work at the moment. You can update 365 by downloading to a share and then running a command line to update office if you don't have SCCM.
  • Thanks 1
Posted
I can’t understand what’s going on with the monthly updates now. A few days ago all our machines jumped into life and patched to the latest version. Then a new patch was released and once again they are all failing.
Posted

@sparkeh

About 50 out of 2000 clients patched Office 365 Proplus 12130.20344 so I disabled the ADR. 12130.20390 still seems to fail. It looks like it's Bits or it's trying to use peer caching even though it's disabled. It fails to fallback to the CDN. Or the CDN is having issues.

 

This reddit thread is helpful.

 

Posted
I ended up going the easy route and buying WSUS Automated Maintenance. It works, and has brought the WSUS console back to being useable. Amazing how Microsoft with its billions of dollars can't add in such relatively simple fixes/maintenance.
  • Thanks 1
Posted

Just because you do something, doesn’t mean that’s what everyone should do.

 

WSUS is fine. Yes it needs maintenance. So does everything Windows-centric.

 

Carry on.

  • Thanks 2
Posted

I get the feeling they want to put it all under Endpoint Manager, where SCCM/EM is leveraging WSUS.

 

But as it's still leveraging WSUS, do you still ultimately get issues where WSUS isn't actually responding?

Posted
I get the feeling they want to put it all under Endpoint Manager, where SCCM/EM is leveraging WSUS.

 

But as it's still leveraging WSUS, do you still ultimately get issues where WSUS isn't actually responding?

From experience, SCCM works with WSUS just fine, pretty speedy actually (faster then if you use WSUS natively).

Posted
I wonder why it isn't affected by these same issues?

I imagine because of the way SCCM works with WSUS. It doesn't simply sit on top of WSUS and use the same work flow that you would if were using WSUS natively.

 

SCCM just leverages WSUS to download the metadata of the updates to determine what's new (according to the rules you set) and then downloads the updates itself.

 

So if you actually open WSUS you are wading through the update catalog, in sccm you are only dealing with the updates you need.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...