locked
PCs not reporting back to WSUS RRS feed

  • Question

  • Hi, I have an organisation with approximately 200 PCs which all receive their updates from a local WSUS Server. However, within that 200 PCs, I have about 6 who will not report back to WSUS.

    I have tried all the usual things like resetting the SIDs, running wuauclt with the various switches and deleting them from WSUS and recreating them but to no avail.

    I can see from the Last Contact column that the PCs are communication with the WSUS Server, but they are just not reporting.

    I have attached the contents of the WindowsUpdate.log from one of the PCs to see if anyone can assist.

    Thanking you all in advance.

    2017-09-28 07:42:51:385 1032 f38 Misc ===========  Logging initialized (build: 7.6.7601.19161, tz: +0100)  ===========
    2017-09-28 07:42:51:401 1032 f38 Misc   = Process: C:\windows\system32\svchost.exe
    2017-09-28 07:42:51:401 1032 f38 Misc   = Module: c:\windows\system32\wuaueng.dll
    2017-09-28 07:42:51:385 1032 f38 Service *************
    2017-09-28 07:42:51:401 1032 f38 Service ** START **  Service: Service startup
    2017-09-28 07:42:51:401 1032 f38 Service *********
    2017-09-28 07:42:51:417 1032 f38 Agent   * WU client version 7.6.7601.19161
    2017-09-28 07:42:51:417 1032 f38 Agent   * Base directory: C:\windows\SoftwareDistribution
    2017-09-28 07:42:51:432 1032 f38 Agent   * Access type: No proxy
    2017-09-28 07:42:51:432 1032 f38 Agent   * Network state: Connected
    2017-09-28 07:43:37:323 1032 f38 Report CWERReporter::Init succeeded
    2017-09-28 07:43:37:323 1032 f38 Agent ***********  Agent: Initializing Windows Update Agent  ***********
    2017-09-28 07:43:37:339 1032 f38 Agent   * Prerequisite roots succeeded.
    2017-09-28 07:43:37:339 1032 f38 Agent ***********  Agent: Initializing global settings cache  ***********
    2017-09-28 07:43:37:339 1032 f38 Agent   * WSUS server: http://server04:81
    2017-09-28 07:43:37:339 1032 f38 Agent   * WSUS status server: http://server04:81
    2017-09-28 07:43:37:339 1032 f38 Agent   * Target group: (Unassigned Computers)
    2017-09-28 07:43:37:339 1032 f38 Agent   * Windows Update access disabled: No
    2017-09-28 07:43:37:370 1032 f38 DnldMgr Download manager restoring 0 downloads
    2017-09-28 07:43:37:385 1032 f38 AU ###########  AU: Initializing Automatic Updates  ###########
    2017-09-28 07:43:37:401 1032 f38 AU AU setting next detection timeout to 2017-09-28 06:43:37
    2017-09-28 07:43:37:401 1032 f38 AU   # WSUS server: http://server04:81
    2017-09-28 07:43:37:401 1032 f38 AU   # Detection frequency: 22
    2017-09-28 07:43:37:401 1032 f38 AU   # Approval type: Scheduled (Policy)
    2017-09-28 07:43:37:401 1032 f38 AU   # Scheduled install day/time: Every day at 16:00
    2017-09-28 07:43:37:401 1032 f38 AU   # Auto-install minor updates: No (Policy)
    2017-09-28 07:43:37:416 1032 f38 AU Setting AU scheduled install time to 2017-09-28 15:00:00
    2017-09-28 07:43:38:037 1032 f38 Report ***********  Report: Initializing static reporting data  ***********
    2017-09-28 07:43:38:037 1032 f38 Report   * OS Version = 6.1.7601.1.0.65792
    2017-09-28 07:43:38:037 1032 f38 Report   * OS Product Type = 0x00000030
    2017-09-28 07:43:38:068 1032 f38 Report   * Computer Brand = Hewlett-Packard
    2017-09-28 07:43:38:068 1032 f38 Report   * Computer Model = HP ProBook 4545s
    2017-09-28 07:43:38:084 1032 f38 Report   * Bios Revision = 68CPD Ver. F.63
    2017-09-28 07:43:38:084 1032 f38 Report   * Bios Name = Default System BIOS
    2017-09-28 07:43:38:084 1032 f38 Report   * Bios Release Date = 2016-05-05T00:00:00
    2017-09-28 07:43:38:084 1032 f38 Report   * Locale ID = 6153
    2017-09-28 07:43:40:210 1032 f38 AU Successfully wrote event for AU health state:0
    2017-09-28 07:43:40:241 1032 f38 AU Initializing featured updates
    2017-09-28 07:43:40:241 1032 f38 AU Found 0 cached featured updates
    2017-09-28 07:43:40:256 1032 f38 AU Successfully wrote event for AU health state:0
    2017-09-28 07:43:40:256 1032 f38 AU Successfully wrote event for AU health state:0
    2017-09-28 07:43:40:256 1032 f38 AU AU finished delayed initialization
    2017-09-28 07:43:40:256 1032 f38 AU #############
    2017-09-28 07:43:40:256 1032 f38 AU ## START ##  AU: Search for updates
    2017-09-28 07:43:40:256 1032 f38 AU #########
    2017-09-28 07:43:40:396 1032 f38 AU <<## SUBMITTED ## AU: Search for updates [CallId = {A1435903-FFBF-46F3-9EFE-A7A458AC30FF}]
    2017-09-28 07:43:45:719 1032 13f4 Agent *************
    2017-09-28 07:43:45:719 1032 13f4 Agent ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2017-09-28 07:43:45:735 1032 13f4 Agent *********
    2017-09-28 07:43:45:735 1032 13f4 Agent   * Online = Yes; Ignore download priority = No
    2017-09-28 07:43:45:735 1032 13f4 Agent   * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2017-09-28 07:43:45:735 1032 13f4 Agent   * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2017-09-28 07:43:45:735 1032 13f4 Agent   * Search Scope = {Machine}
    2017-09-28 07:43:45:735 1032 13f4 Setup Checking for agent SelfUpdate
    2017-09-28 07:43:45:735 1032 13f4 Setup Client version: Core: 7.6.7601.19161  Aux: 7.6.7601.19161
    2017-09-28 07:43:45:983 1032 13f4 Misc Validating signature for C:\windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:
    2017-09-28 07:43:46:278 1032 13f4 Misc Microsoft signed: NA
    2017-09-28 07:43:46:278 1032 13f4 Misc WARNING: Cab does not contain correct inner CAB file.
    2017-09-28 07:43:46:278 1032 13f4 Misc Validating signature for C:\windows\SoftwareDistribution\SelfUpdate\wuident.cab with dwProvFlags 0x00000080:
    2017-09-28 07:43:46:294 1032 13f4 Misc Microsoft signed: NA
    2017-09-28 07:43:46:433 1032 13f4 Setup Wuident for the managed service is valid but not quorum-signed. Skipping selfupdate.
    2017-09-28 07:43:46:433 1032 13f4 Setup Skipping SelfUpdate check based on the /SKIP directive in wuident
    2017-09-28 07:43:46:433 1032 13f4 Setup SelfUpdate check completed.  SelfUpdate is NOT required.
    2017-09-28 07:44:04:638 1032 13f4 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
    2017-09-28 07:44:04:638 1032 13f4 PT   + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://server04:81/ClientWebService/client.asmx
    2017-09-28 07:44:04:669 1032 13f4 PT WARNING: Cached cookie has expired or new PID is available
    2017-09-28 07:44:04:669 1032 13f4 PT Initializing simple targeting cookie, clientId = 0808a43b-6114-4e6b-a0f2-8c9f4a3330b7, target group = , DNS name = PCname.Domain.local
    2017-09-28 07:44:04:669 1032 13f4 PT   Server URL = http://servername:81/SimpleAuthWebService/SimpleAuth.asmx
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: GetCookie failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: SOAP Fault: 0x00012c
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING:     faultstring:Fault occurred
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING:     ErrorCode:ServerChanged(4)
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING:     Message:Server rolled back since last call to GetCookie
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING:     Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/GetCookie"
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING:     ID:b36eaaca-a8f7-42c6-afd8-f5c5b2aa0cb1
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: PTError: 0x80244015
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: GetCookie_WithRecovery failed : 0x80244015
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: RefreshCookie failed: 0x80244015
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: RefreshPTState failed: 0x80244015
    2017-09-28 07:44:04:902 1032 13f4 PT WARNING: Sync of Updates: 0x80244015
    2017-09-28 07:44:04:933 1032 13f4 PT WARNING: Cached cookie has expired or new PID is available
    2017-09-28 07:44:04:933 1032 13f4 PT Initializing simple targeting cookie, clientId = 0808a43b-6114-4e6b-a0f2-8c9f4a3330b7, target group = , DNS name = PCNAME.DOMAIN.local
    2017-09-28 07:44:04:933 1032 13f4 PT   Server URL = http://servername:81/SimpleAuthWebService/SimpleAuth.asmx
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING: RefreshCache failure, error = 0x8024400E, soap client error = 7, soap error code = 400, HTTP status code = 200
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING: SOAP Fault: 0x000190
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING:     faultstring:There was an exception running the extensions specified in the config file. ---> Maximum request length exceeded.
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING:     ErrorCode:(null)(0)
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING:     Message:(null)
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING:     Method:(null)
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING:     ID:(null)
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING: PTError: 0x8024400e
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING: RefreshCache_WithRecovery failed: 0x8024400e
    2017-09-28 07:44:04:979 1032 13f4 PT WARNING: SyncCache: Emergency cleanup of the ServerUpdateInfo due to failure in RefreshCache
    2017-09-28 07:44:06:857 1032 13f4 PT WARNING: SyncCache failed : 0x8024400e
    2017-09-28 07:44:06:857 1032 13f4 PT WARNING: SyncServerUpdatesInternal failed: 0x8024400e
    2017-09-28 07:44:06:857 1032 13f4 Agent   * WARNING: Failed to synchronize, error = 0x8024400E
    2017-09-28 07:44:30:090 1032 13f4 Agent   * WARNING: Exit code = 0x8024400E
    2017-09-28 07:44:30:090 1032 13f4 Agent *********
    2017-09-28 07:44:30:090 1032 13f4 Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2017-09-28 07:44:30:090 1032 13f4 Agent *************
    2017-09-28 07:44:30:090 1032 13f4 Agent WARNING: WU client failed Searching for update with error 0x8024400e
    2017-09-28 07:44:30:106 1032 474 AU >>##  RESUMED  ## AU: Search for updates [CallId = {A1435903-FFBF-46F3-9EFE-A7A458AC30FF}]
    2017-09-28 07:44:30:106 1032 474 AU   # WARNING: Search callback failed, result = 0x8024400E
    2017-09-28 07:44:30:106 1032 474 AU   # WARNING: Failed to find updates with error code 8024400E
    2017-09-28 07:44:30:106 1032 474 AU #########
    2017-09-28 07:44:30:106 1032 474 AU ##  END  ##  AU: Search for updates [CallId = {A1435903-FFBF-46F3-9EFE-A7A458AC30FF}]
    2017-09-28 07:44:30:106 1032 474 AU #############
    2017-09-28 07:44:30:106 1032 474 AU Successfully wrote event for AU health state:0
    2017-09-28 07:44:30:106 1032 474 AU AU setting next detection timeout to 2017-09-28 11:44:30
    2017-09-28 07:44:30:106 1032 474 AU Setting AU scheduled install time to 2017-09-28 15:00:00
    2017-09-28 07:44:30:106 1032 474 AU Successfully wrote event for AU health state:0
    2017-09-28 07:44:30:106 1032 474 AU Successfully wrote event for AU health state:0
    2017-09-28 07:44:35:677 1032 13f4 Report REPORT EVENT: {5CFCD252-6B35-474B-BDA4-1736BF88DCD0} 2017-09-28 07:44:30:090+0100 1 148 101 {00000000-0000-0000-0000-000000000000} 0 8024400e AutomaticUpdates Failure Software Synchronization Windows Update Client failed to detect with error 0x8024400e.
    2017-09-28 07:44:35:817 1032 13f4 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2017-09-28 07:44:35:817 1032 13f4 Report WER Report sent: 7.6.7601.19161 0x8024400e(0) 0000000-0000-0000-0000-000000000000 Scan 0 1 AutomaticUpdates {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} 0
    2017-09-28 07:46:28:721 1032 1270 DtaStor Default service for AU is {9482F4B4-E343-43B6-B170-9A65BC822C77}
    2017-09-28 07:46:28:721 1032 1270 Agent AddTargetedServiceMapping: A1ED24B0-D495-429A-9BD8-597E02013760 -> 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7
    2017-09-28 07:46:28:799 1032 1270 Agent WARNING: could not delete Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Services\a1ed24b0-d495-429a-9bd8-597e02013760 service registry key 0x80070002
    2017-09-28 07:46:28:799 1032 1270 Agent WARNING: Failed to delete service from the backup store, error = 0x80070002
    2017-09-28 07:46:28:799 1032 1270 Agent RemoveTargetedServiceMapping: A1ED24B0-D495-429A-9BD8-597E02013760 -> 3DA21691-E39D-4DA6-8A4B-B43877BCB1B7
    2017-09-28 07:58:00:865 1032 13f4 PT WARNING: Cached cookie has expired or new PID is available
    2017-09-28 07:58:00:865 1032 13f4 PT Initializing simple targeting cookie, clientId = 0808a43b-6114-4e6b-a0f2-8c9f4a3330b7, target group = , DNS name = PCNAME.DOMAIN.local
    2017-09-28 07:58:00:865 1032 13f4 PT   Server URL = http://servername:81/SimpleAuthWebService/SimpleAuth.asmx
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING: GetCookie failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING: SOAP Fault: 0x00012c
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING:     faultstring:Fault occurred
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING:     ErrorCode:ServerChanged(4)
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING:     Message:Server rolled back since last call to GetCookie
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING:     Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/GetCookie"
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING:     ID:0bac003a-85ba-4aaf-aa60-9f7fd3bf76a6
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING: PTError: 0x80244015
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING: GetCookie_WithRecovery failed : 0x80244015
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING: RefreshCookie failed: 0x80244015
    2017-09-28 07:58:00:912 1032 13f4 PT WARNING: RefreshPTState failed: 0x80244015
    2017-09-28 07:58:00:928 1032 13f4 PT WARNING: Cached cookie has expired or new PID is available
    2017-09-28 07:58:00:928 1032 13f4 PT Initializing simple targeting cookie, clientId = 0808a43b-6114-4e6b-a0f2-8c9f4a3330b7, target group = , DNS name = PCNAME.DOMAIN.local
    2017-09-28 07:58:00:928 1032 13f4 PT   Server URL = http://servername:81/SimpleAuthWebService/SimpleAuth.asmx
    2017-09-28 07:58:00:959 1032 13f4 PT WARNING: No updates found from server; serverID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2017-09-28 07:58:00:990 1032 13f4 Report Uploading 1 events using cached cookie, reporting URL = http://servername:81/ReportingWebService/ReportingWebService.asmx
    2017-09-28 07:58:01:005 1032 13f4 Report Reporter successfully uploaded 1 events.

    Thursday, September 28, 2017 9:14 AM

All replies

  • Hi,

    >>I have tried all the usual things like resetting the SIDs,

    Do you mean you have followed the operation within the article below and deleted the client :

    https://gallery.technet.microsoft.com/scriptcenter/Reset-WSUS-Authorization-2e26d1b0

    If the issue persists ,I'd suggest you try to reset WSUS components:

    https://support.microsoft.com/en-sg/help/971058/how-do-i-reset-windows-update-components

    Also ,please try to perform wsus cleanup:

    https://gallery.technet.microsoft.com/scriptcenter/fd39c7d4-05bb-4c2d-8a99-f92ca8d08218

    https://community.spiceworks.com/scripts/show/2998-adamj-clean-wsus

     

    Best Regards,

    Elton


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, September 29, 2017 7:41 AM
  • As Elton mentions, My script will fix your problem. Elton, thanks for mentioning it :)

    Have a peek at my Adamj Clean-WSUS script. It is the last WSUS Script you will ever need!

    http://community.spiceworks.com/scripts/show/2998-adamj-clean-wsus

    What it does:

    1. Add WSUS Index Optimization to the database to increase the speed of many database operations in WSUS by approximately 1000-1500 times faster.
    2. Remove all Drivers from the WSUS Database (Default; Optional).
    3. Shrink your WSUSContent folder's size by declining multiple types of updates including by default any superseded updates, preview updates, expired updates, Itanium updates, and beta updates. Optional extras: Language Packs, IE7, IE8, IE9, IE10, Embedded, NonEnglishUpdates, ComputerUpdates32bit, WinXP.
    4. Remove declined updates from the WSUS Database.
    5. Clean out all the synchronization logs that have built up over time (configurable, with the default keeping the last 14 days of logs).
    6. Compress Update Revisions.
    7. Remove Obsolete Updates.
    8. Computer Object Cleanup (configurable, with the default of deleting computer objects that have not synced within 30 days).
    9. Application Pool Memory Configuration to display the current private memory limit and easily set it to any configurable amount including 0 for unlimited. This is a manual execution only.
    10. Checks to see if you have a dirty database, and if you do, fixes it. This is primarily for Server 2012 WSUS, and is a manual execution only.
    11. Run the Recommended SQL database Maintenance script on the actual SQL database.
    12. Run the Server Cleanup Wizard.

    It will email the report out to you or save it to a file, or both.

    Although the script is lengthy, it has been made to be super easy to setup and use so don't over think it. There are some prerequisites and instructions at the top of the script. After installing the prerequisites and configuring the variables for your environment (email settings only if you are accepting all the defaults), simply run:

    .\Clean-WSUS.ps1 -FirstRun

    If you wish to view or increase the Application Pool Memory Configuration, or run the Dirty Database Check, you must run it with the required switch. See Get-Help .\Clean-WSUS.ps1 -Examples

    If you're having trouble, there's also a -HelpMe option that will create a log so you can send it to me for support.

    If after running my script, some of those clients still fail to report, run the following from an affected client in an administrative command prompt.

    net stop bits
    net stop wuauserv
    reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v AccountDomainSid /f
    reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v PingID /f
    reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientId /f
    reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientIDValidation /f
    rd /s /q "C:\WINDOWS\SoftwareDistribution"
    net start bits
    net start wuauserv
    wuauclt /resetauthorization /detectnow


    Adam Marshall, MCSE: Security
    http://www.adamj.org

    Saturday, September 30, 2017 2:29 PM