Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Update Services > Re: PCs no longer report to WSUS console "Failed to filter search resu

Reply
Thread Tools Display Modes

Re: PCs no longer report to WSUS console "Failed to filter search resu

 
 
PA Bear [MS MVP]
Guest
Posts: n/a

 
      12-05-2009
[[ Right pew, wrong church. Forwarded to WSUS newsgroup
(microsoft.public.windows.server.update_services) via crosspost as a
convenience to OP.

On the web:
http://www.microsoft.com/communities...pdate_services

In your newsreader:
news://msnews.microsoft.com/microsof...pdate_services
]]


JeffS wrote:
> 88 of my 104 pc's stopped reporting to the WSUS console on 11/21/09. The
> pc's that aren't reporting started getting this message in their
> WindowsUpdate.log: WARNING: "Failed to filter search results", error =
> 0x8024000B. I've tried reinstalling the Client Version 3, and it didn't
> work. I also deleted the Software Distribution Folder and reset the
> SusClientID, PingID and AccountDomainSid. We have Client Side Targeting.
> Our WSUS version is 3.1.6001.65. Here's a copy of one day's detection
> cycle. Does anyone have any suggestions as to how I can get the pc's to
> report again?
>
> 2009-12-01 20:20:42:359 1116 644 AU AU found 0 updates for install at
> shutdown 2009-12-01 20:23:45:937 1116 328 AU ########### AU:
> Uninitializing
> Automatic Updates ###########
> 2009-12-01 20:23:45:937 1116 cec Agent * WARNING: Failed to filter
> search
> results, error = 0x8024000B
> 2009-12-01 20:23:49:515 1116 cec Agent *********
> 2009-12-01 20:23:49:515 1116 cec Agent ** END ** Agent: Finding updates
> [CallerId = AutomaticUpdates]
> 2009-12-01 20:23:49:515 1116 cec Agent *************
> 2009-12-01 20:23:49:578 1116 328 Service *********
> 2009-12-01 20:23:49:578 1116 328 Service ** END ** Service: Service
> exit
> [Exit code = 0x240001]
> 2009-12-01 20:23:49:578 1116 328 Service *************
> 2009-12-01 20:24:55:484 1100 278 Misc =========== Logging initialized
> (build: 7.2.6001.788, tz: -0500) ===========
> 2009-12-01 20:24:55:515 1100 278 Misc = Process:
> C:\WINDOWS\System32\svchost.exe
> 2009-12-01 20:24:55:546 1100 278 Misc = Module:
> C:\WINDOWS\system32\wuaueng.dll
> 2009-12-01 20:24:55:484 1100 278 Service *************
> 2009-12-01 20:24:55:562 1100 278 Service ** START ** Service: Service
> startup 2009-12-01 20:24:55:578 1100 278 Service *********
> 2009-12-01 20:24:55:640 1100 278 Agent * WU client version 7.2.6001.788
> 2009-12-01 20:24:56:218 1100 278 Agent * Base directory:
> C:\WINDOWS\SoftwareDistribution
> 2009-12-01 20:24:56:250 1100 278 Agent * Access type: No proxy
> 2009-12-01 20:24:56:265 1100 278 Agent * Network state: Connected
> 2009-12-01 20:25:42:437 1100 278 Agent *********** Agent: Initializing
> Windows Update Agent ***********
> 2009-12-01 20:25:42:437 1100 278 Agent *********** Agent: Initializing
> global settings cache ***********
> 2009-12-01 20:25:42:437 1100 278 Agent * WSUS server: http://cc-dns-2
> 2009-12-01 20:25:42:437 1100 278 Agent * WSUS status server:
> http://cc-dns-2 2009-12-01 20:25:42:437 1100 278 Agent * Target group:
> CC
> 2009-12-01 20:25:42:437 1100 278 Agent * Windows Update access disabled:
> No 2009-12-01 20:26:00:375 1100 278 DnldMgr Download manager restoring 0
> downloads
> 2009-12-01 20:26:01:281 1100 278 AU ########### AU: Initializing
> Automatic
> Updates ###########
> 2009-12-01 20:26:01:281 1100 278 AU AU setting next detection timeout to
> 2009-12-02 01:26:01
> 2009-12-01 20:26:01:281 1100 278 AU # WSUS server: http://cc-dns-2
> 2009-12-01 20:26:01:281 1100 278 AU # Detection frequency: 11
> 2009-12-01 20:26:01:281 1100 278 AU # Target group: CC
> 2009-12-01 20:26:01:281 1100 278 AU # Approval type: Scheduled (Policy)
> 2009-12-01 20:26:01:281 1100 278 AU # Scheduled install day/time: Every
> day at 11:00
> 2009-12-01 20:26:01:281 1100 278 AU # Auto-install minor updates: Yes
> (User preference)
> 2009-12-01 20:26:01:281 1100 278 AU # Will interact with non-admins
> (Non-admins are elevated)
> 2009-12-01 20:26:01:625 1100 278 AU Setting AU scheduled install time to
> 2009-12-02 16:00:00
> 2009-12-01 20:26:01:625 1100 278 AU AU finished delayed initialization
> 2009-12-01 20:26:09:375 1100 278 Report *********** Report: Initializing
> static reporting data ***********
> 2009-12-01 20:26:09:375 1100 278 Report * OS Version =
> 5.1.2600.3.0.65792
> 2009-12-01 20:26:09:718 1100 278 Report * Computer Brand = Dell Computer
> Corporation
> 2009-12-01 20:26:09:718 1100 278 Report * Computer Model = OptiPlex
> GX260
>
> 2009-12-01 20:26:09:843 1100 278 Report * Bios Revision = A09
> 2009-12-01 20:26:09:859 1100 278 Report * Bios Name = Default System
> BIOS
> 2009-12-01 20:26:09:859 1100 278 Report * Bios Release Date =
> 2004-11-01T00:00:00
> 2009-12-01 20:26:09:859 1100 278 Report * Locale ID = 1033
> 2009-12-01 20:26:10:093 1100 278 AU #############
> 2009-12-01 20:26:10:093 1100 278 AU ## START ## AU: Search for updates
> 2009-12-01 20:26:10:093 1100 278 AU #########
> 2009-12-01 20:26:10:093 1100 278 AU <<## SUBMITTED ## AU: Search for
> updates
> [CallId = {E89B3AF7-192F-44D1-B7CB-18B453F9DBE3}]
> 2009-12-01 20:26:19:765 1100 c08 Agent *************
> 2009-12-01 20:26:19:765 1100 c08 Agent ** START ** Agent: Finding updates
> [CallerId = AutomaticUpdates]
> 2009-12-01 20:26:19:765 1100 c08 Agent *********
> 2009-12-01 20:26:19:765 1100 c08 Agent * Online = Yes; Ignore download
> priority = No
> 2009-12-01 20:26:19:765 1100 c08 Agent * Criteria = "IsHidden=0 and
> IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or
> IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and
> IsAssigned=1 or IsHidden=0 and IsInstalled=1 and
> DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or
> IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and
> IsAssigned=1 and RebootRequired=1"
> 2009-12-01 20:26:19:765 1100 c08 Agent * ServiceID =
> {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
> 2009-12-01 20:26:19:765 1100 c08 Agent * Search Scope = {Machine}
> 2009-12-01 20:26:19:875 1100 c08 Misc Validating signature for
> C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default \wuident.cab:
> 2009-12-01 20:26:20:109 1100 c08 Misc Microsoft signed: Yes
> 2009-12-01 20:26:20:156 1100 c08 Misc Validating signature for
> C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default \wuident.cab:
> 2009-12-01 20:26:20:187 1100 c08 Misc Microsoft signed: Yes
> 2009-12-01 20:26:20:281 1100 c08 Misc Validating signature for
> C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default \wsus3setup.cab:
> 2009-12-01 20:26:20:296 1100 c08 Misc Microsoft signed: Yes
> 2009-12-01 20:26:20:406 1100 c08 Setup *********** Setup: Checking
> whether
> self-update is required ***********
> 2009-12-01 20:26:20:406 1100 c08 Setup * Inf file:
> C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default \wsus3setup.inf
> 2009-12-01 20:26:20:453 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\cdm.dll: target version = 7.2.6001.788, required
> version
> = 7.1.6001.65
> 2009-12-01 20:26:20:453 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuapi.dll: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:468 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuapi.dll.mui: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:484 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuauclt.exe: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:484 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuaucpl.cpl: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:515 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuaucpl.cpl.mui: target version = 7.2.6001.788,
> required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:515 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuaueng.dll: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:546 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuaueng.dll.mui: target version = 7.2.6001.788,
> required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:546 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wucltui.dll: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:578 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wucltui.dll.mui: target version = 7.2.6001.788,
> required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:578 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wups.dll: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:578 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wups2.dll: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:593 1100 c08 Setup Update NOT required for
> C:\WINDOWS\system32\wuweb.dll: target version = 7.2.6001.788, required
> version = 7.1.6001.65
> 2009-12-01 20:26:20:609 1100 c08 Setup WARNING: Warning: Setup callback
> ReportProgress failed: 0x8007000d
> 2009-12-01 20:26:20:609 1100 c08 Setup * IsUpdateRequired = No
> 2009-12-01 20:26:33:406 1100 278 AU AU received policy change subscription
> event
> 2009-12-01 20:26:33:406 1100 278 AU AU Options changed from policy.
> 2009-12-01 20:26:33:406 1100 278 AU ########### AU: Policy change
> processed
> ###########
> 2009-12-01 20:26:33:406 1100 278 AU # Policy changed, AU refresh
> required
> = No
> 2009-12-01 20:26:33:406 1100 278 AU # WSUS server: http://cc-dns-2
> 2009-12-01 20:26:33:406 1100 278 AU # Detection frequency: 11
> 2009-12-01 20:26:33:406 1100 278 AU # Target group: CC
> 2009-12-01 20:26:33:406 1100 278 AU # Approval type: Scheduled (Policy)
> 2009-12-01 20:26:33:406 1100 278 AU # Scheduled install day/time: Every
> day at 11:00
> 2009-12-01 20:26:33:421 1100 278 AU # Auto-install minor updates: Yes
> (User preference)
> 2009-12-01 20:26:33:421 1100 278 AU AU settings changed through Policy.
> 2009-12-01 20:26:33:453 1100 278 AU ElevateNonAdmins policy changed
> 2009-12-01 20:26:33:453 1100 278 AU Setting AU scheduled install time to
> 2009-12-02 16:00:00
> 2009-12-01 20:26:45:093 1100 c08 PT +++++++++++ PT: Synchronizing server
> updates +++++++++++
> 2009-12-01 20:26:45:093 1100 c08 PT + ServiceId =
> {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL =
> http://cc-dns-2/ClientWebService/client.asmx
> 2009-12-01 20:26:45:156 1100 c08 PT WARNING: Cached cookie has expired or
> new PID is available
> 2009-12-01 20:26:45:171 1100 c08 PT Initializing simple targeting cookie,
> clientId = 345aabf8-ba5c-4e26-a8cc-4893dd00a94c, target group = CC, DNS
> name
> = twd91.cc.sunywcc.edu
> 2009-12-01 20:26:45:171 1100 c08 PT Server URL =
> http://cc-dns-2/SimpleAuthWebService/SimpleAuth.asmx
> 2009-12-01 20:27:22:812 1100 c08 PT +++++++++++ PT: Synchronizing
> extended
> update info +++++++++++
> 2009-12-01 20:27:22:812 1100 c08 PT + ServiceId =
> {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL =
> http://cc-dns-2/ClientWebService/client.asmx
> 2009-12-01 23:58:48:500 1100 278 AU ########### AU: Uninitializing
> Automatic Updates ###########
> 2009-12-01 23:58:48:500 1100 c08 Agent * WARNING: Failed to filter
> search
> results, error = 0x8024000B
> 2009-12-01 23:58:49:562 1100 c08 Agent *********
> 2009-12-01 23:58:49:562 1100 c08 Agent ** END ** Agent: Finding updates
> [CallerId = AutomaticUpdates]
> 2009-12-01 23:58:49:562 1100 c08 Agent *************
> 2009-12-01 23:58:49:687 1100 278 Service *********
> 2009-12-01 23:58:49:687 1100 278 Service ** END ** Service: Service
> exit
> [Exit code = 0x240001]
> 2009-12-01 23:58:49:687 1100 278 Service *************


 
Reply With Quote
 
 
 
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      12-05-2009

JeffS wrote:

> 88 of my 104 pc's stopped reporting to the WSUS console on 11/21/09.


1. As a starting point, what is the latest (dated 11/21/09, of course) Last
Reported Date for those 88 PCs.

2. What activity is recorded in the %ProgramFiles%\Update
Services\Logfiles\Change.Log after the reporting time noted in #1?

> Does anyone have any suggestions as to how I can get the pc's to report
> again?


> {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7},
> Server URL = http://cc-dns-2/ClientWebService/client.asmx


> 2009-12-01 23:58:48:500 1100 c08 Agent * WARNING: Failed to filter
> search
> results, error = 0x8024000B


My working theory is to try to find out what was changed between the time
the last client successfully reported, and the next client failed to detect.

In addition to what may be recorded in the Change.Log, if you have any other
information on what might have changed during that time on 11/21/09, it
might be useful information.

--
Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)

My Blog: http://onsitechsolutions.spaces.live.com
Microsoft WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
 
JeffS
Guest
Posts: n/a

 
      12-09-2009
I can't find change.log , or the Update Services or Logfiles folders, on any
of my systems, except for the server. The only changes that have been made
are the latest Windows Updates and McAfee dats. And they were distributed to
all the systems, working and not working. The last day the 88 workstations
reported is 11/20/09.

"Lawrence Garvin [MVP]" wrote:

> JeffS wrote:
>
> > 88 of my 104 pc's stopped reporting to the WSUS console on 11/21/09.

>
> 1. As a starting point, what is the latest (dated 11/21/09, of course) Last
> Reported Date for those 88 PCs.
>
> 2. What activity is recorded in the %ProgramFiles%\Update
> Services\Logfiles\Change.Log after the reporting time noted in #1?
>
> > Does anyone have any suggestions as to how I can get the pc's to report
> > again?

>
> > {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7},
> > Server URL = http://cc-dns-2/ClientWebService/client.asmx

>
> > 2009-12-01 23:58:48:500 1100 c08 Agent * WARNING: Failed to filter
> > search
> > results, error = 0x8024000B

>
> My working theory is to try to find out what was changed between the time
> the last client successfully reported, and the next client failed to detect.
>
> In addition to what may be recorded in the Change.Log, if you have any other
> information on what might have changed during that time on 11/21/09, it
> might be useful information.
>
> --
> Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
> Principal/CTO, Onsite Technology Solutions, Houston, Texas
> Microsoft MVP - Software Distribution (2005-2009)
>
> My Blog: http://onsitechsolutions.spaces.live.com
> Microsoft WSUS Website: http://www.microsoft.com/wsus
> My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin
>
> .
>

 
Reply With Quote
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      12-09-2009
"JeffS" <> wrote in message
news:A7A8E699-47EE-41FA-BF3D-...
>I can't find change.log , or the Update Services or Logfiles folders, on
>any
> of my systems, except for the server.


Well, that's good. That's the only system they should be on.

> The only changes that have been made
> are the latest Windows Updates and McAfee dats.


Well, yeah.. I kinda assumed that -- (although I doubt there's any McAfee
entries in the Change.LOG).

But don't lose sight of the fact that the McAfee signature files were
updated. Have you reviewed the McAfee scan logs to make sure that McAfee
didn't do anything undesirable or inappropriate to those systems after they
got broken?

> The last day the 88 workstations reported is 11/20/09.


Good. Let's start by looking at all of the actual Change.LOG entries for
11/20/09.

Oh, and what we really need is the *TIME* of the client who was the *LAST*
to report.
As was my intention to ask for -- the ACTUAL value from the WSUS Admin UI
contained in the "Last Reported Date" column.

As a general concept -- we deal in facts here -- it's the only reliable way
to determine what is happening, what is not happening, and make educated
analyses. As such, generally I'd prefer not to have your interpretations of
what you're reading. To be blunt (but no disrespect intended), if your
interpretations were sufficient, you wouldn't be posting here for help. :-)

--
Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)

My Blog: http://onsitechsolutions.spaces.live.com
Microsoft WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
 
JeffS
Guest
Posts: n/a

 
      12-10-2009
I've compared the McAfee files from a reporting and a nonreporting system and
there are no differences, and no messages that would indicate a problem with
the dat files. The last client reported its status at 10:03pm Eastern
Standard Time on 11/20/2009. Below is the change.log from the server for
11/20/09 and 11/21/09. Please tell me if there's anything else you may need.


2009-11-20 07:00:22.893 UTC WSUS configuration has been changed
2009-11-20 07:00:25.705 UTC Deleted deployment(Install) of Definition Update
for Windows Defender - KB915597 (Definition 1.69.643.0)
UpdateID:C29B3C79-077B-4E0B-890E-F26EAE78C088 Revision Number:100
TargetGroup:All Computers
2009-11-20 07:00:25.939 UTC Downloading retried
2009-11-21 07:00:03.285 UTC WSUS configuration has been changed
2009-11-21 07:00:04.081 UTC Successfully deployed deployment(Install) of
Update for Internet Explorer 8 Compatibility View List for Windows 7
(KB975364) by SUNYWCC\PPA1 UpdateID:EDF201ED-83ED-41A3-BF9D-A69A7D8377A6
Revision Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.144 UTC Successfully deployed deployment(Install) of
Update for Internet Explorer 8 Compatibility View List for Windows 7 for
x64-based Systems (KB975364) by SUNYWCC\PPA1
UpdateID:BA09E2B0-3518-4E56-A7BC-F1954B028A68 Revision Number:100
TargetGroup:All Computers
2009-11-21 07:00:04.191 UTC Successfully deployed deployment(Install) of
Update for Internet Explorer 8 Compatibility View List for Windows XP
(KB975364) by SUNYWCC\PPA1 UpdateID:B717344F-D1DE-4990-95B9-F9B03A04DA4A
Revision Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.347 UTC Successfully deployed deployment(Install) of
Definition Update for Windows Defender - KB915597 (Definition 1.69.725.0) by
SUNYWCC\PPA1 UpdateID:422D22A4-4BE6-4FF0-965D-B9EA2A95C4A9 Revision
Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.394 UTC Successfully deployed deployment(Install) of
Update for Microsoft Office Word 2007 (KB974561) by SUNYWCC\PPA1
UpdateID:9452E2DD-399E-430C-A7F6-81065B8BD447 Revision Number:103
TargetGroup:All Computers
2009-11-21 07:00:04.425 UTC Successfully deployed deployment(Install) of
Group Policy Preference Client Side Extensions for Windows XP (KB943729) by
SUNYWCC\PPA1 UpdateID:B71AD818-A99D-4309-B350-83FE9399B437 Revision
Number:104 TargetGroup:All Computers
2009-11-21 07:00:04.550 UTC Successfully deployed deployment(Install) of
Windows Malicious Software Removal Tool - November 2009 (KB890830) by
SUNYWCC\PPA1 UpdateID:A45B9BA4-5ADD-4702-95CB-BE38B0681172 Revision
Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.566 UTC Successfully deployed deployment(Install) of
Windows Malicious Software Removal Tool - November 2009 (KB890830) - IE
Version by SUNYWCC\PPA1 UpdateID:E84E2425-851C-42A1-BE61-ACB7509C2937
Revision Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.613 UTC Successfully deployed deployment(Install) of
Windows Malicious Software Removal Tool x64 - November 2009 (KB890830) by
SUNYWCC\PPA1 UpdateID:074773A4-6F6B-427A-A90D-B3D3E43D1A9E Revision
Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.644 UTC Successfully deployed deployment(Install) of
Update for Windows XP (KB968930) by SUNYWCC\PPA1
UpdateID:1C81AA3A-6F53-499D-B519-2A81CFBAA1DB Revision Number:100
TargetGroup:All Computers
2009-11-21 07:00:04.722 UTC Successfully deployed deployment(Install) of
Definition Update for Windows Defender - KB915597 (Definition 1.69.881.0) by
SUNYWCC\PPA1 UpdateID:9BC1539D-34AE-41F3-9E2F-065AAEF90779 Revision
Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.800 UTC Successfully deployed deployment(Install) of
Definition Update for Windows Defender - KB915597 (Definition 1.69.995.0) by
SUNYWCC\PPA1 UpdateID8B08FA9-A5D8-4511-9735-CCCD4F72703D Revision
Number:100 TargetGroup:All Computers
2009-11-21 07:00:04.925 UTC Successfully deployed deployment(Install) of
Definition Update for Windows Defender - KB915597 (Definition 1.71.26.0) by
SUNYWCC\PPA1 UpdateID6E41B55-40DF-4F7B-86E9-3F13409F82D7 Revision
Number:100 TargetGroup:All Computers
2009-11-21 07:00:06.972 UTC Downloading retried





"Lawrence Garvin [MVP]" wrote:

> "JeffS" <> wrote in message
> news:A7A8E699-47EE-41FA-BF3D-...
> >I can't find change.log , or the Update Services or Logfiles folders, on
> >any
> > of my systems, except for the server.

>
> Well, that's good. That's the only system they should be on.
>
> > The only changes that have been made
> > are the latest Windows Updates and McAfee dats.

>
> Well, yeah.. I kinda assumed that -- (although I doubt there's any McAfee
> entries in the Change.LOG).
>
> But don't lose sight of the fact that the McAfee signature files were
> updated. Have you reviewed the McAfee scan logs to make sure that McAfee
> didn't do anything undesirable or inappropriate to those systems after they
> got broken?
>
> > The last day the 88 workstations reported is 11/20/09.

>
> Good. Let's start by looking at all of the actual Change.LOG entries for
> 11/20/09.
>
> Oh, and what we really need is the *TIME* of the client who was the *LAST*
> to report.
> As was my intention to ask for -- the ACTUAL value from the WSUS Admin UI
> contained in the "Last Reported Date" column.
>
> As a general concept -- we deal in facts here -- it's the only reliable way
> to determine what is happening, what is not happening, and make educated
> analyses. As such, generally I'd prefer not to have your interpretations of
> what you're reading. To be blunt (but no disrespect intended), if your
> interpretations were sufficient, you wouldn't be posting here for help. :-)
>
> --
> Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
> Principal/CTO, Onsite Technology Solutions, Houston, Texas
> Microsoft MVP - Software Distribution (2005-2009)
>
> My Blog: http://onsitechsolutions.spaces.live.com
> Microsoft WSUS Website: http://www.microsoft.com/wsus
> My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin
>

 
Reply With Quote
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      12-10-2009
"JeffS" <> wrote in message
news:06E2664F-C653-4F42-978B-...

> The last client reported its status at 10:03pm Eastern
> Standard Time on 11/20/2009. Below is the change.log from the server for
> 11/20/09 and 11/21/09. Please tell me if there's anything else you may
> need.


What Time Zone are you in?


--
Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)

My Blog: http://onsitechsolutions.spaces.live.com
Microsoft WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
 
JeffS
Guest
Posts: n/a

 
      12-11-2009
Eastern Standard Time. I'm in New York.

"Lawrence Garvin [MVP]" wrote:

> "JeffS" <> wrote in message
> news:06E2664F-C653-4F42-978B-...
>
> > The last client reported its status at 10:03pm Eastern
> > Standard Time on 11/20/2009. Below is the change.log from the server for
> > 11/20/09 and 11/21/09. Please tell me if there's anything else you may
> > need.

>
> What Time Zone are you in?
>
>
> --
> Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
> Principal/CTO, Onsite Technology Solutions, Houston, Texas
> Microsoft MVP - Software Distribution (2005-2009)
>
> My Blog: http://onsitechsolutions.spaces.live.com
> Microsoft WSUS Website: http://www.microsoft.com/wsus
> My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin
>

 
Reply With Quote
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      12-11-2009
"JeffS" <> wrote in message
news:06E2664F-C653-4F42-978B-...

> The last client reported its status at 10:03pm Eastern Standard Time on
> 11/20/2009.


So, you're in Eastern Standard Time, which means these logfiles are GMT-7,
which also tells us that the first entry is at 12:00:22am on 11/20 -- 22
hours before the last client reported...
and goes through 11/21 at 12:00:06am on 11/21 -- about 2 hours after the
last client reported.

We're interested only in events after 11/21 05:00:00 (GMT), so the entries
on 11/21 are where we'll focus our efforts:

Recalling that the original reported message is:
>> WARNING: "Failed to filter search results", error = 0x8024000B.


One possible cause is the KB968930 update -- which is known to have issues
on a couple of fronts. Let's remove the approval for this update as a
diagnostic step, to eliminate it as a possible cause. There are some
incidents that have suggested it may need to be an exclusive update but
isn't coded as one, and there's a known conflict with the Confliker
protections documented in KB962007.

Why are *multiple* versions of Definition Updates being approved? Please
approve the *LATEST* version and *DECLINE* all obsolete versions! This is
another possible cause of the problem -- conflicts caused by multiple
Definition Updates being approved.

In addition... here's an interesting observation . . . on my system all four
of the Windows Defender updates listed below were released *AFTER* Nov
21st!!!

1.69.725 was released on 11/23/09
1.69.881 was released on 11/26/09
1.69.995 was released on 11/30/09
1.71.26 was released on 12/3/09

so how the heck are they showing up in a Change.log timestamped November
21st???

The answer is this: All of the above Defender Definition updates were
*REVISED*...

1.69.725 REV 101 was released on 11/23/09
1.69.881 REV 101 was released on 11/26/09
1.69.995 REV 101 was released on 11/30/09
1.71.26 REV101 was released on 12/3/09

all of the packages below are REV100 packages, and since then should have
been EXPIRED.

Also, my review of the Definition Updates listing shows two packages for
v1.71.26, and that's not likely appropriate either.

"Definition Update for Windows Defender - KB915597 (Definition 1.71.26.0)"
is shown as superseded by 1.71.129, 1.71.269, 1.71.346, and 1.71.471
and is at Rev. 101 dated 12/3/09. This update is now expired.

"Definition Update for Microsoft Windows Defender - KB915597 (Definition
1.71.26.0)"
which you'll note does not conform to the standard update title naming
scheme used by Defender Definition Updates in WSUS,
has *NO* supercession data == this is a defective update!!! (but is not the
one processed in this instance on 11/21).
This update is Rev. 101 dated 11/19/09. This update is now expired.

If these updates have not been properly maintained (e.g. expired updates
declined, superceded updates declined, and only the *current* definition
update is approved) -- this is a very likely source of the issue with the
message "Failing to filter search results", as those Defender Update likely
had defective metadata, which may well be contributing to this issue.

In addition, this scenario is exactly why:
== the "Automatically approve new revisions of updates that are already
approved" option should be enabled
== the "Automatically decline updates when a new revision causes them to
expire" option should be enabled
== the Server Cleanup Wizard should be run weekly

all of the above particularly apply when WSUS is used to deploy Definition
Updates

if the above three are in force, it's likely this issue (if, in fact, caused
by one or more of these Defender updates) would have been self-correcting,
or might have never occurred.

If that were the case -- a WSUS server, today, would have only four Defender
Definition Updates approved for deployment:
1.71.346 released on 11/30
1.71.471 released on 12/3
1.71.570 released on 12/7
1.71.700 released on 12/10
the former three of which are superceded by the last.

Incidentally, the 0x8024400B error code is documented in KB958040
(September, 2008),
http://support.microsoft.com/default.aspx/kb/958040
and I found it via a simple Bing search on the error code "0x8024400B"

If cleaning up the approvals for the expired/superceded Windows Defender
Definition Updates does not resolve the issue, you should also try the
remediation steps documented in that KB article.



== Windows Management Framework Core ==
> 2009-11-21 07:00:04.644 UTC Successfully deployed deployment(Install) of
> Update for Windows XP (KB968930) by SUNYWCC\PPA1
> UpdateID:1C81AA3A-6F53-499D-B519-2A81CFBAA1DB Revision Number:100
> TargetGroup:All Computers



== Windows Defender Definition Updates ==
> 2009-11-21 07:00:04.347 UTC Successfully deployed deployment(Install) of
> Definition Update for Windows Defender - KB915597 (Definition 1.69.725.0)
> by
> SUNYWCC\PPA1 UpdateID:422D22A4-4BE6-4FF0-965D-B9EA2A95C4A9 Revision
> Number:100 TargetGroup:All Computers


> 2009-11-21 07:00:04.722 UTC Successfully deployed deployment(Install) of
> Definition Update for Windows Defender - KB915597 (Definition 1.69.881.0)
> by
> SUNYWCC\PPA1 UpdateID:9BC1539D-34AE-41F3-9E2F-065AAEF90779 Revision
> Number:100 TargetGroup:All Computers


> 2009-11-21 07:00:04.800 UTC Successfully deployed deployment(Install) of
> Definition Update for Windows Defender - KB915597 (Definition 1.69.995.0)
> by
> SUNYWCC\PPA1 UpdateID8B08FA9-A5D8-4511-9735-CCCD4F72703D Revision
> Number:100 TargetGroup:All Computers


> 2009-11-21 07:00:04.925 UTC Successfully deployed deployment(Install) of
> Definition Update for Windows Defender - KB915597 (Definition 1.71.26.0)
> by
> SUNYWCC\PPA1 UpdateID6E41B55-40DF-4F7B-86E9-3F13409F82D7 Revision
> Number:100 TargetGroup:All Computers



== Windows Malicious Software Removal Tool ==
> 2009-11-21 07:00:04.550 UTC Successfully deployed deployment(Install) of
> Windows Malicious Software Removal Tool - November 2009 (KB890830) by
> SUNYWCC\PPA1 UpdateID:A45B9BA4-5ADD-4702-95CB-BE38B0681172 Revision
> Number:100 TargetGroup:All Computers


> 2009-11-21 07:00:04.566 UTC Successfully deployed deployment(Install) of
> Windows Malicious Software Removal Tool - November 2009 (KB890830) - IE
> Version by SUNYWCC\PPA1 UpdateID:E84E2425-851C-42A1-BE61-ACB7509C2937
> Revision Number:100 TargetGroup:All Computers


> 2009-11-21 07:00:04.613 UTC Successfully deployed deployment(Install) of
> Windows Malicious Software Removal Tool x64 - November 2009 (KB890830) by
> SUNYWCC\PPA1 UpdateID:074773A4-6F6B-427A-A90D-B3D3E43D1A9E Revision
> Number:100 TargetGroup:All Computers




== IE8 Compatibility View List ==
> 2009-11-21 07:00:04.081 UTC Successfully deployed deployment(Install) of
> Update for Internet Explorer 8 Compatibility View List for Windows 7
> (KB975364) by SUNYWCC\PPA1 UpdateID:EDF201ED-83ED-41A3-BF9D-A69A7D8377A6
> Revision Number:100 TargetGroup:All Computers


> 2009-11-21 07:00:04.144 UTC Successfully deployed deployment(Install) of
> Update for Internet Explorer 8 Compatibility View List for Windows 7 for
> x64-based Systems (KB975364) by SUNYWCC\PPA1
> UpdateID:BA09E2B0-3518-4E56-A7BC-F1954B028A68 Revision Number:100
> TargetGroup:All Computers


> 2009-11-21 07:00:04.191 UTC Successfully deployed deployment(Install) of
> Update for Internet Explorer 8 Compatibility View List for Windows XP
> (KB975364) by SUNYWCC\PPA1 UpdateID:B717344F-D1DE-4990-95B9-F9B03A04DA4A
> Revision Number:100 TargetGroup:All Computers



> 2009-11-21 07:00:04.394 UTC Successfully deployed deployment(Install) of
> Update for Microsoft Office Word 2007 (KB974561) by SUNYWCC\PPA1
> UpdateID:9452E2DD-399E-430C-A7F6-81065B8BD447 Revision Number:103
> TargetGroup:All Computers



> 2009-11-21 07:00:04.425 UTC Successfully deployed deployment(Install) of
> Group Policy Preference Client Side Extensions for Windows XP (KB943729)
> by
> SUNYWCC\PPA1 UpdateID:B71AD818-A99D-4309-B350-83FE9399B437 Revision
> Number:104 TargetGroup:All Computers


--
Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)

My Blog: http://onsitechsolutions.spaces.live.com
Microsoft WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
WindowsUpdate_8024D00A WindowsUpdate_dt000 Michelle Windows Vista Performance 14 03-01-2008 10:42 AM
Re: Vista Ultimate - Cannot search Error8007370D Robert Aldwinckle Windows Vista Performance 11 02-27-2008 06:34 AM
Re: Update Error 80070246 Robert Aldwinckle Windows Vista Performance 2 02-12-2008 08:15 PM
Is Windows Vista index-based full-text search powerful enough? Peter Frank Windows Vista File Management 47 03-23-2007 05:54 PM
Search filter "qoutes" not working (RC2) Luther Windows Vista File Management 0 10-11-2006 12:23 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59