Good Morning (on the east coast). Anyone familiar with error 1072? Failed deployment
I can scan a machine but when I try to deploy patches, I get this message
error 1072 the specified service has been marked for deletion
Good Morning (on the east coast). Anyone familiar with error 1072? Failed deployment
I can scan a machine but when I try to deploy patches, I get this message
error 1072 the specified service has been marked for deletion
Hi Everyone,
I am sure I am not the only person/company that want to test there patches fore they are deployed into there live environment.
We are using Shavlik Protect to patch our desktops and servers, however there is a need to delay patches to our servers. Here is what I am trying to achieve:
Microsoft release updates on patch Tuesday (Week 1)
I deploy my updates to our testing environment and start testing applications (Week 1-4)
Microsoft release updates on patch Tuesday (This is now Week 5 in my schedule but back to Week 1 for the 4 weekly)
Week 5 is my Patching week. Any patches Microsoft have released before there next patch Tuesday have been included. I now want to patch my servers but I do not want to include any patches that would have downloaded from the 2nd patch Tuesday as I havent yet tested any of these updates.
I need to know if there is a way I can make this happen. I have been looking at smart filters and the possibility of using a filter which says "Patch Release Date" "Is Greater then" "x" where X would be the days in question.
Has anyone else got a similar setup or another way in which they delay patches for servers but not for desktops?
Everyone's help is greatly appreciated.
Regards,
Scott
Is there anyway to modify the extend reboot timer behavior for agents? I was just curious if it was possible to prevent users from having the ability to click extend timer multiple times (up to the force action limit). I would love for the agent to popup, allow extend timer, hide for awhile, and then popup again. In other words, be more of a nuisance for users to convince them to reboot their systems. Also would love the option to automatically minimize the window after clicking extend timer.
Thanks,
Chris
Hello again,
I was just curious what the expected behavior for an agent is in the following two scenarios? No complaints or issues, just curious about the expected behavior:
Thanks Again,
Chris
Hi, could someone please tell me if Citrix XenApp 7.5 is supported with Shavlik Protect 9.1?
I think that according to the following link it is - http://www.shavlik.com/support/protect/supported-products/
However if I scan a server that has XenApp 7.5 installed it doesn't return any outstanding Citrix patches when I definitely know that there are outstanding patches available for the product.
I'm new to Shavlik so please forgive me if the answer to my question is obvious.
Thanks.
Steve
The Shavlik support article "How To Cancel / Delete Scheduled Tasks" (How To Cancel / Delete Scheduled Tasks) does not provide a method for canceling a scheduled task, only deleting.
How does one cancel a running scheduled scan, that is not using Windows Task scheduler?
Thanks
Can someone point me in the direction of a document that explains the "Machine View" display selection logic? It seems to me that if I bring up Machine View for a group that includes 29 members, I should see a listing od 29 machines, not "There are no items to show in this view". Thank you.
Is it possible to install the Protect console on a management workstation rather than having to log into the installed Protect server in order to run scans? If so, is there documentation on this? If not, will this be supported in the future?
Is there an expected release date for Protect 9.2?
Hello fellow patchers,
Wondering if anyone has noticed this issue on their machines. We use Shavlik and WSUS to install our patches on Windows 7 - 64 machines. Came across an interest dilemma on our machines. We have been loosing disk space to c:\windows\logs\cbs, most machines are sitting at 40 gigs plus of logs and it seems like the files are not being archived correctly.The older machines with smaller HDD are not able to boot to domain due to this issue.
Shavlik can we add this folder to the cleanup itscript?
Thank you,
Robin
I am trying to schedule regular scans to aid in generating some reports. My question is this: I have 4 consoles and 7 different domains to scan which require domain specific credentials. How can I schedule multiple scans to run from a particular console on different domains?
Thanks,
Kara
I have been getting this error for a while now. I am not behind a proxy or content filtering. Regular Microsoft updates download fine on the server itself but will not download through patch management. 3rd party updates such as firefox, adobe and java all download with no issue. other than Microsoft updates return the error in the subject line. Current version: Shavlik Protect Standard 9.1.0 Build: 4511
Any guidance is much appreciated!
Thanks!
Is it possible to copy all missing patches to the computer and start the installation when the users shuts down the system?
This article provides a list of required web addresses for the Protect application.
This issue occurs if one or more web addresses required by the Protect console server are blocked.
To resolve this issue, ensure that these Web addresses required by Protect are accessible and allowed through firewalls, proxies, or web filters:
If you require the IP addresses to create exceptions you can find the IP addresses used for XML.shavlik.com here. To obtain the IP for vendor sites you can ping the site for the current IP address or contact the vendor to obtain this information.
Shavlik Protect, All versions
vCenter Protect 8.x
Shavlik Rebrands
The purpose of this article is to show how an agent can be installed on a target machine with no policy using a manual installation script. This can be useful to make sure that the agents are installed on target machines prior to an image being cloned and installed on multiple targets. Agents with pre-existing policies cannot be cloned due to certificate and name resolution issues.
The Agent installer file is the STPlatformupdater.exe and can be found in the following location on your console machine:
C:\ProgramData\LANDesk\Shavlik Protect\Console\DataFiles\ STPlatformupdater.exe
Or downloaded from here:
9.0 version
http://xml.shavlik.com/data/Protect/v9/90/Protect/1182/STPlatformUpdater.exe
9.1 version
http://xml.shavlik.com/data/protect/v9/91/protect/4334/stplatformupdater.exe
This is a three-step process:
1. Agent Installation: (blank-slate agent install)
To do that you can run the STPlatformUpdater.exe on the machine you will create your base image on. When the agent install completes and prompts you to register (either through the cloud or to a console) you can cancel the wizard. You now have the base agent installed. You can clone the image now.
2. Agent Registration: (performed after the machine is created)
The agent must register with the console once each machine has been imaged. This should occur after the machine name changes, the SSID changes, etc. (i.e. the target machine should be a unique machine at this point before proceeding forward). You can run this command (with proper information):
STAgentManagement.exe -register -p silent=true -p serverUri=https://consolename:3121 -p policy=policyname -p AuthType=SharedPassphrase -p passphrase="passphrase"
You can verify success by looking at the RegistrationLog.txt on the agent machine. This is what you should see in the log:
Agent Registration Operation Log.
Created DayOfTheWeek, MM DD, YYYY HH:MM:SS
Stopping agent services for configuration changes.
Stopping STAgent.
STAgent stopped.
Stopping STDispatch.
STDispatch stopped.
Agent Id is 'StringOfLettersAndNumbers'.
Checking for compatibility with existing software.
The environment is compatible with agent operation.
Registering agent.
Registering agent with authentication type SharedPassphrase.
Registering agent with host 'https://consolename:3121'.
Received an immediate registration response. Completing registration now.
Configuration changes complete.
Restarting agent services after configuration changes.
Restarting STDispatch.
Updating agent proxy configuration.
Restarting STDispatch.
3. Agent Check-in: (performed after the agent has been registered)
The agent must check-in to complete the agent registration. You can either wait for the scheduled check-in interval or you can kick it off from the CMD prompt. You can run this command:
STAgentManagement.exe -checkin -noconsole
You can get a full list of switches for STAgentManagement.exe by using /? from the command line.
Related articles:
Installing Agents Using A Manual Installation Script
Scripted Agent Install May Fail During Registration Due To NetBIOS Resolution Failure
Shavlik Protect 9.x
The purpose of this document is to explain the best practices for Windows Automatic Update configuration in a Shavlik environment.
When Windows Automatic Update is configured to check for updates, even if it is not configured to download or install them, it can cause slow deployments with Shavlik.
1. Set Automatic Updates to "Never check for updates".
2. Stop the Windows Update Service and set the service to Manual. (The service will start as needed)
3. Make sure you don't have a custom location setting for "Specify intranet Microsoft updater service location". This is set in in Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update. Remove this setting.
All
Purpose
This document will address an issue where scanning by OU and excluding machines with FQDN fails to exclude the machine.
Symptoms
You are scanning from a Machine Group setup by OU. You exclude machine(s) by FQDN but they are scanned.
Cause
The OU scans the machine using netbios rather than FQDN so excluding machines by FQDN will not work.
Resolution
Exclude the machines using the netbios name instead of FQDN.
Affected Product(s)
Protect 9.x
This document will provide information where Help > Refresh File hangs, Scans hangs at Step 2: Import New Definitions and Protect crashing when clicking on the GUI during these processes.
You are using Protect 9.1 and one the following issues occurs:
In recent months, our Content Team has been making massive data updates to get ready for the upcoming release of Protect 9.2. These changes include associating/updating patches with their CVE information which require a large amount of processing. A small number of our customers have run into definition import issues explained in the description.
The purpose of this workaround is to disable the definition imports occurring before scans and schedule the imports to run in the background throughout the week. The idea hear is to have the database updated by the time you need to scan machines.
Automated: Depending on timing, this method may not fix all instances of the issue.
Manual:
The upcoming release of Protect 9.2 is not affected by this issue. Current ETA on release is mid-October. We highly suggest all customers update to Protect 9.2 once it is available.
Protect 9.x
Hello,
Version:
Shavlik Protect Standard 9.1.0
Build: 4334
I have a issue that i didn.t experienced before. For example i am making a scan, i have 3086255 MS15-097 detected as missing, after that i deploy the patches and after a new scan i have 0 missing patches.
After a while (some hours), if i make a new scan i have MS15-097 detected again as missing.
Checked event viewer and logs and is seems that the patch was not installed. Then why Shavlik says it is installed (based on the second scan) and on the third scan it appears as missing ?
This is affecting not one patch consoles, there are different patch consoles on different clients.
I have one Windows 10 Professional machine set up with an agent. I have noticed after the agent does a patch scan, the operating system reports as Window 10 Pro. After a check-in or asset scan, it shows as Windows 8.1 Pro. The machine originally was Windows 7 Professional and was upgraded to Windows 10 after the release date. I am not sure if the agent was removed and reinstalled after the upgrade.
We are running protect 9.1 build 4511 and the agent is version 9.1.4334.0.
The machine is installing patches for Windows 10, so it is just a reporting issue. I haven't seen anyone else report this yet, but maybe I missed it.