Quantcast
Channel: LANDESK User Community : Popular Discussions - Patch Manager
Viewing all 3522 articles
Browse latest View live

Printer Issues after Security and Patch Updates

$
0
0

Has anyone out there seen any issues with printers after doing Security and Patch updates via LANDESK?  We've been seeing a fair amount of issues where printers have to be reinstalled after the LANDESK Security and Patch scan is run against the machine and patches are applied.  This seems to affect both locally-installed and network printers, Windows XP and 7, desktops and laptops.  We're only pushing Microsoft and LANDESK updates, so it's entirely possible that one of the Microsoft updates is causing it, but we haven't been able to identify which one (or ones) might be causing it.

 

Thanks in advance!


Patch Management via powershell script

$
0
0

Hi,

     Is there any power shell script available by which i can query the list of updates available, trigger updates and perform patch management ? I am new to LanDesk.

VulScan Using Excessive Memory?

$
0
0

Hello,

 

We seem to have a common issues with several users in our organization. VulScan will kick off periodically throughout the day and use about 380K of the available memory which is leading to an extremely bogged down system. Has anyone experience this in your environment? Also, what logs could I check to find any abnormalities? I appreciate any advice!

 

- Stoj

vulscan.exe

$
0
0

We previously had the agent configuration setup to scan for vulnerabilities, spyware, everything. But whenever vulscan runs, our users start calling complaining their system is slow and we look and see vulscan hogging resources. Is there a way to make it less resource-intensive? Otherwise, I suppose I will have to schedule the security scan seperately

How to exclude patches from scanning by Product?

$
0
0

My environment does not use Mozilla Thunderbird.  I would like to automatically send all Mozilla Thunderbird patches into the "Do Not Scan" status.

Since there isn't a "Product" field/column, can someone confirm if this works or not?

do not scan.png

LDMS 9.5 "Gather Historical Information" crashing everytime

$
0
0

As the title states "Gather Historical Information" is crashing during the task towards the end at "Removing historical information more than 30 days old ...".

 

The console crashes every time at this point. When I try to schedule the task for later, the task runs once then crashes, and then it fails to run again the next day. The error is "Failed, task handler exception".

 

This is preventing me from having accurate informaiton in the patch and compliance area. Any ideas?

Downloading Java SE 6 Update 51

$
0
0

Has anyone figured out how to actually download the latest v.6 Java update? They only list the v.7 stuff now on their standard download page. I found a page where you can download old versions, but it only went up to the last v.6 version - Update 43. The LANDesk bulletin says: "login Oracle Technical Network to get these patches" but after mucking around on the Oracle site for 15 minutes, I can find no such logon.

 

Thanks!

Patch Distribution Global

$
0
0

We have a certain set of users that have to be running an older version of Java....about 10 computers

 

Till this point we've always distributed patches with Enable Global Autofix

 

What's the best way to enable the latest version for Java to get distributed for the entire district (thousands of devices) and exclude these 10 machines only from the Java update


KB... does not apply, or is blocked by another condition on your computer.

$
0
0

Hi,

 

I have a core server Landesk 9 SP3 et agent are on SP3 too.

 

I have a lot of patch especially .NET patch ( ndp*****.exe ) that are detected by landesk but the installation failed.

When I try to install it by hand I have the following message :

-     KB***** does not apply, or is blocked by another condition on your computer.

          With this message I try to shutdown all the appz that run on server et reintall it. I got the same message

 

Here's some patches that are detected by Landesk but cannot be installed on the system :

MS11-100

MS11-044

MS11-066

MS12-016

...

 

I think that the problem come with the process of detection for these patches !

 

Do you have also these problems ? and have you find a solution to avoid it ?

 

Big Thanks !

How to vulscan from batch package?

$
0
0

Hello,

 

i'm currently trying to build a batch package, which does a normal autofix vulscan (which works fine if i schedule the appropriate scan and repair settings). After autofixing the client i would like to clean up a bit (diasble java autoupdate, etc) so i thought about creating a batch-package.

 

the batch looks like this:

 

"%LD_CLIENT_DIR%\vulscan.exe" /agentbehavior=61
<some other regedit-commands>

 

But this unfortunately doesn't work.

vulscan.exe is running into a timeout after 10 minutes. The vulscan.log says: "Timed out waiting for another instance of vulscan"

 

I also tried to add ldrunner.exe to the package:

 

install\ldrunner.exe "%LD_CLIENT_DIR%\vulscan.exe" /agentbehavior=61
<some other regedit-commands>

 

But this ends up in the same timeout.

 

Does anyone have an idea how to fix this?

 

Thanks & greets from germany,

Dirk

Value stored in Inventory for Reboot Needed in Affected Computers

$
0
0

In Patch and Compliance if you Right Click on a detected vulnerability and choose Affected computers the Column Set shows a Reboot Needed with a value of 1 or 0 (zero). Does anyone know if this value is getting pulled from inventory? If so does anyone know where it is located? I would like to create a query showing what machines I have that need to be rebooted. This is in LDMS 9.5 SP2

 

Reboot Needed.jpg

Patch download location log

$
0
0

I am moving from patching with config manager to LANDesk and I am trying to figure out how to get the clients to download patches from a local preferred server rather than the core server.  Our patches are stored in \\coreserver\ldlogon\patch.  I have created shares on our file servers, downloaded the patches to the core and then robocopied the content out to the desired preferred servers.  When I start to run patches, they seem to download from the core server rather than the local preferred server.  I'm looking for a log that can tell me where the patches are downloaded from and some ideas to troubleshoot preferred servers for patching.  The preferred servers are working great for software distribution.  It just seems like they don't work for patches.  I would appreciate any help!!

VulScan Using Excessive Memory?

$
0
0

Hello,

 

We seem to have a common issues with several users in our organization. VulScan will kick off periodically throughout the day and use about 380K of the available memory which is leading to an extremely bogged down system. Has anyone experience this in your environment? Also, what logs could I check to find any abnormalities? I appreciate any advice!

 

- Stoj

Windows 7 patches failing on workstation (log attached)

$
0
0

While attempting to patch workstations I have one which appeared to fail on only Windows patches but Office, Adobe etc patched correctly. 

 

The error details are - Error:"C:\Windows\system32\wusa.exe" returned failure code exit (2149842967)

 

I have attached the vulscan log.

 

If anyone has any recommendations, please let me know!

 

Thank you for reading.

 

Jonathan

vulscan.exe is Causing UAC Prompt after Login

$
0
0

After deploying an updated agent configuration to some Windows systems, I get the following UAC prompt:

 

vulscan uac prompt.png

 

Why is this?  I'm not even sure which logs would help; there's also nothing apparent in Event Viewer.


How to create custom definition to block a Mac application?

$
0
0

I see how to create a custom definition in Patch & Compliance but it is not apparent to me how to use it to block a Macintosh application. Does any one have any insite on this?

High CPU Usage by ISSUSER.exe

$
0
0

On LD 9.6 SP1 client I'm seeing issues with ISSUSER.exe running at 100% of one core and sometimes faulting.

Once suggestion was to replace the jscript.v55 file, but that has not resolved the issue.

 

Looking at the application errors  in the diagnostic data in inventory I'm seeing the following

2015-05-29 16_20_06-Inventory - BRDROEDE3NKNWZ1 - __Remote.png

So it appears the LIBEAY32MT.dll is where it's faulting at with an exception code of c0000005

 

Any advice?

Vulscan Scan Times in Local Scheduler Wrong

$
0
0

Hello LANDesk Community,

 

recently I discovered a strange behavior of our vulscan tasks and hopefully you can provide some help or hints.

We did not notice the issue back with LANDesk Management Suite (LDMS) 9.6 without service pack.

A few weeks ago we updated to LDMS 9.6 SP2 (2015-0706B BASE + 9.60.2.72A LDMS).

 

Afterwards we see that tasks executed from the core server are still fine.

However tasks that are scheduled locally on the servers to be patched by landesk seem to run at different times than originally planned.

 

That being said I will give you a rough roundup about the environment and the issue itself.

 

 

Environment

Core Server

OS: Windows Server 2012 R2, English

LDMS: 9.6 SP2 (2015-0706B BASE + 9.60.2.72A LDMS), English

Time format: US

 

Server(s) to be patched

OS: Windows 2008, 2008R2, 2012, 2012 R2, German/English

Time format: US/German

 

Agent Configuration (Scan Only)

Distribution and Patch --- Patch-Only Settings --- Scan options

Type = vulnerabilities + custom definitions
Autofix = not enabled

Distribution and Patch --- Patch-Only Settings --- Scan options --- Schedule

Start [Date] at 11:30:00

Repeat after: 3 Days

Additional random delay: up to 1 hour and at least 30 minutes

This should result in scanning between 12:00 and 12:30 (mealtime).

I would like to use time ranges instead but I can not see how to set a limit at 12:30 then.


Planned Tasks (Repair Only)

We schedule the repair of patches by repair tasks referring to custom groups including the patch definitions.
Tuesday at 04:15 (am)
Saturday at 04:15 (am)

 

Maintenance Window

Tuesday 04:10 (am) - 05:00 (am)

Saturday 04:10 (am) - 05:00 (am)

 

Reboot Time Window

Tuesday 04:10 (am) - 05:00 (am)

Saturday 04:10 (am) - 05:00 (am)

 

 

 

Issue

The following is an example of one server with Windows Server 2012 R2, English + US time format.

With a scan every three days and repair tasks running two times a week you should expect a maximum of two new vulscan logfiles.

However I got four of them.

One of them is correct, a second one was my failure while the remaining two leave me puzzled.

 

vulscan3.log - Code 402 (only scan) at 12th of October around 17:00 <- only scan is correct, time is totally wrong

vulscan2.log - Code 403 (autofix) at 12th of October around 21:00 <- no clue where that comes from

vulscan1.log - Code 403 (autofix) at 12th of October around 4:15 <- everything is fine here

vulscan.log - Code 403 (autofix) at 12th of October around 4:19 <- my failure -.-"

 

So we are looking at vulscan3.log and vulscan2.log.

 

The time of vulscan3 reappears in the localsch.exe /Tasks |more with the following information:

Filter 1 : [Auto delay] State=(Not ready) Min=(30) Max=(60).

It seems that the scan is the one supposed to run from 12:00 to 12:30 (see above).

Since we do not have any other other task with this specific delay I am pretty sure it is.

But why is the task planned for 17:00 instead of 12:00?

 

Vulscan2 leaves me without any clue.

Within the logfile it is written "Parent process: 13088 (LANDESKAgentBootStrap.exe)".

However the only agent setting directly related to scanning the devices is the one supposed to run between 12:00 and 12:30.

Any chance to track down where that task comes from?

 

 

 

Conclusion

One task (vulscan3) with times of +5 hours to the planned task and another one that seems to come out of nowhere.

Hopefully you can give me some hints how to find the source of these problems.


Best regards,
Timo Liedtke

Windows 10 & Detection Rules

$
0
0

I've noticed that most of the third party software that LANDesk provides patching for has in their detection rules Windows 10, but it is not selected as an option.  Will LANDesk be supporting patching of Windows 10 as well as the third party applications that can run on Windows 10?

 

We are running 9.6 with SP2.

Security Activity -> Activity Not Updating Dynamically

$
0
0

I have a question about the Activity view not updating dynamically under Security activity.

 

We are in the process of upgrading Landesk 9.0 to 9.6 and I've been using this view (Security activity -> Activity) to monitor the agent updates to 9.6. It has been working good showing me if the AV portion has been updated. It appears now, though, the activity is about 5 days late. Has anyone experienced this issue?

Viewing all 3522 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>