Thursday 11 February 2016

Update Classifications



Critical updates : Broadly released fixes for specific problems addressing critical, non-security related bugs.

Definition Updates: Updates to anti-malware or other definition files.

Feature Packs: New product functionality usually included in the next full product release.

Security Updates: Broadly released fixes for specific products, addressing security issues.

Service Packs: Cumulative sets of all hotfixes, security updates, critical updates, and updates created since the release of the product. Service packs might also contain a limited number of customer-requested design changes or features.

Tools: Utilities or features that aid in accomplishing a task or set of tasks.

Update Rollups: Cumulative sets of hotfixes, security updates, critical updates, and updates packaged together for easy deployment. A rollup generally targets a specific area, such as security, or a specific component, such as Internet Information Services (IIS).

Updates:  Broadly released fixes for specific problems addressing non-critical, non-security related bugs.

SCCM 2012 Log Details

SCCM 2012 Log Details


Client Side Application Deployment related log files:
·         AppDiscovery.log
·         AppEnforce.log
·         AppIntentEval.log
·         CAS.log
·         CIAgent.log
·         CIDownloader.log
·         CIStateStore.log
·         CIStore.log
·         CITaskMgr.log
·         DataTransferService.log
·         DCMAgent.log
·         DCMReporting.log
·         LocationServices.log
·         PolicyAgent.log

Server Side Software Update Logs:
·                SUPsetup.log - Installation of SUP Site Role.
·                WCM.log, WSUSCtrl.log - Configuration of WSUS Server/SUP.
·                WSyncMgr.log - SMS/WSUS Updates Synchronization Issues.
·                Objreplmgr.log - Policy Issues for Update Assignments/CI Version Info policies.
·                RuleEngine.log - Auto Deployment Rules.

Client Side Software Update Logs:
·         UpdatesDeployment.log - Deployments, SDK, UX.
·         UpdatesHandler.log - Updates, Download.
·         ScanAgent.log - Online/Offline scans, WSUS location requests.
·         WUAHandler.log - Update status (missing/installed - verbose logging), WU interaction.
·         UpdatesStore.log - Update status (missing/installed).
·         %windir%\WindowsUpdate.log - Scanning/Installation of updates.

SCCM 2012 Log file Reference:

·         adctrl.log - Records enrollment processing activity.
·         ADForestDisc.log - Records Active Directory Forest Discovery actions.
·         ADService.log - Records account creation and security group details in Active Directory.
·         adsgdis.log - Records Active Directory Security Group Discovery actions.
·         adsysdis.log - Records Active Directory System Discovery actions.
·         adusrdis.log - Records Active Directory User Discovery actions.
·         ccm.log - Records client push installation activities.
·         CertMgr.log - Records the certificate activities for intra-site communications.
·         chmgr.log - Records activities of the client health manager.
·         Cidm.log - Records changes to the client settings by the Client Install Data Manager (CIDM).
·         colleval.log - Records details about when collections are created, changed, and deleted by the Collection Evaluator.
·         compmon.log - Records the status of component threads monitored for the site server.
·         compsumm.log - Records Component Status Summarizer tasks.
·         ComRegSetup.log - Records the initial installation of COM registration results for a site server.
·         ConfigMgrPrereq.log - Records pre-requisite component evaluation and installation activities.
·         dataldr.log - Records information about the processing of Management Information Format (MIF) files and hardware inventory in the Configuration Manager database.
·         ddm.log - Records activities of the discovery data manager.
·         despool.log - Records incoming site-to-site communication transfers.
·         distmgr.log - Records details about package creation, compression, delta replication, and information updates.
·         EPCtrlMgr.log - Records information about the synchronization of malware threat information from the Endpoint Protection site system role server into the Configuration Manager database.
·         EPMgr.log - Records the status of the Endpoint Protection site system role.
·         EPSetup.log - Provides information about the installation of the Endpoint Protection site system role.
·         EnrollSrv.log - Records activities of the Enrollment service process.
·         EnrollWeb.log - Records activities of the enrollment website process.
·         fspmgr.log - Records activities of the fallback status point site system role.
·         hman.log - Records information about site configuration changes, and the publishing of site information in Active Directory Domain Services.
·         Inboxast.log - Records the files that are moved from the management point to the corresponding INBOXES folder on the site server.
·         inboxmgr.log - Records file transfer activities between inbox folders.
·         inboxmon.log - Records the processing of inbox files and performance counter updates.
·         invproc.log - Records the forwarding of MIF files from a secondary site to its parent site.
·         migmctrl.log - Records information for Migration actions involving migration jobs, shared distribution points, and distribution point upgrades.
·         mpcontrol.log - Records the registration of the management point with WINS. Records the availability of the management point every 10 minutes.
·         mpfdm.log - Records the actions of the management point component that moves client files to the corresponding INBOXES folder on the site server.
·         mpMSI.log - Records details of about the management point installation.
·         MPSetup.log - Records the management point installation wrapper process.
·         netdisc.log - Records Network Discovery actions.
·         ntsvrdis.log - Records the discovery activity of site system servers.
·         Objreplmgr - Records the processing of object change notifications for replication.
·         offermgr.log - Records advertisement updates.
·         offersum.log - Records the summarization of deployment status messages.
·         OfflineServicingMgr.log - Records the activities of applying updates to operating system image files.
·         outboxmon.log - Records the processing of outbox files and performance counter updates.
·         PerfSetup.log - Records the results of the installation of performance counters.
·         PkgXferMgr.log - Records the actions of the SMS Executive component that is responsible for sending content from a primary site to a remote distribution point.
·         policypv.log - Records updates to the client policies to reflect changes to client settings or advertisements.
·         rcmctrl.log - Records the activities of database replication between sites in the hierarchy.
·         replmgr.log - Records the replication of files between the site server components and the Scheduler component.
·         ResourceExplorer.log - Records errors, warnings, and information about running the Resource Explorer.
·         ruleengine.log - Records details about Auto Deployment Rules around the identification, content download, and update group and deployment creation.
·         Sched.log - Records details about site-to-site job and package replication.
·         schedule.log - Records the activities for standard sender content scheduling jobs.
·         sender.log - Records the files that transfer by file-based replication between sites.
·         sinvproc.log - Records information about the processing of software inventory data to the site database.
·         sitecomp.log - Records details about the maintenance of the installed site components on all site system servers in the site.
·         sitectrl.log - Records site setting changes made to site control objects in the database.
·         sitestat.log - Records the availability and disk space monitoring process of all site systems.
·         SmsAdminUI.log - Records Configuration Manager console activity.
·         SMSAWEBSVCSetup.log - Records the installation activities of the application catalog web service.
·         smsbkup.log - Records output from the site backup process.
·         smsdbmon.log - Records database changes.
·         SMSENROLLSRVSetup.log - Records the installation activities of the enrollment web service.
·         SMSENROLLWEBSetup.log - Records the installation activities of the enrollment website.
·         smsexec.log - Records the processing of all site server component threads.
·         SMSFSPSetup.log - Records messages generated by the installation of a fallback status point.
·         SMSPORTALWEBSetup.log - Records the installation activities of the application catalog web site.
·         SMSProv.log - Records WMI provider access to the site database.
·         smstsvc.log - Records information about the installation, use, and removal of a Windows service that is used to test network connectivity and permissions between servers, using the computer account of the server initiating the connection.
·         srsrpMSI.log - Records detailed results of the reporting point installation process from the MSI output.
·         srsrpsetup.log - Records results of the reporting point installation process.
·         Srvacct.log - Records the maintenance of accounts when the site uses standard security.
·         statesys.log - Records the processing of state system messages.
·         statmgr.log - Records the writing of all status messages to the database.
·         swmproc.log - Records the processing of metering files and settings.
SCCM Policy
·         PolicyAgent.log - Requests policies by using the Data Transfer service.
·         PolicyAgentProvider.log - Records policy changes.
·         PolicyEvaluator.log - Records new policy settings.


Inventory
·         InventoryAgent.log - Creates discovery data records (DDRs) and hardware and software inventory records.
·         inventoryprovider.log – Records all inventory details
DCM
·         DCMAgent.log:  Records high-level information about the evaluation, conflict reporting, and remediation of configuration items and applications.
·         CIAgent.log: Records details about the process of remediation and compliance for compliance settings, software updates, and application management.
·         CMReporting.log :  Records information about reporting policy platform results into state messages for configuration items.
·         DcmWmiProvider.log Records information about reading configuration item synclets from Windows Management Instrumentation (WMI).   
Client Operation Log Files
·         CAS.log  - Content Access service. Maintains the local package cache on the client.
·         Ccm32BitLauncher.log - Records actions for starting applications on the client marked as “run as 32bit”.
·         CcmEval.log - Records Configuration Manager client status evaluation activities and details for components that are required by the Configuration Manager client.
·         CcmEvalTask.log - Records the Configuration Manager client status evaluation activities that are initiated by the evaluation scheduled task.
·         CcmExec.log - Records activities of the client and the SMS Agent Host service. This log file also includes information about enabling and disabling wake-up proxy.
·         CcmMessaging.log - Records activities related to communications between the client and management points.
·         CCMNotificationAgent.log - Records activities related to client notification operations.
Client Installation Log Files

·         ccmsetup.log - Records ccmsetup tasks for client setup, client upgrade, and client removal. Can be used to troubleshoot client installation problems.
·         ccmsetup-ccmeval.log - Records ccmsetup tasks for client status and remediation.
·         CcmRepair.log - Records the repair activities of the client agent.
·         client.msi.log - Records setup tasks performed by client.msi. Can be used to troubleshoot client installation or removal problems.

Client Location Log
·         ClientLocation.log - Site assignment tasks.
·         LocationServices.log - Finds management points and distribution points.

Software Distribution Logs
·         Policyagnet.log - Requests policies software distribution.
·         PolicyEvaluator.log - Records new policy settings about new deployment
·         Execmgr.log - Records advertisements that run
·         DataTransferService.log - Records all BITS communication for policy or package access.
·         ContentTransferManager.log - Schedules the Background Intelligent Transfer Service (BITS) or the Server Message Block (SMB) to download or to access SMS packages

Admin Console Log Files
·         RepairWizard.log - Records errors, warnings, and information about the process of running the Repair Wizard.
·         ResourceExplorer.log - Records errors, warnings, and information about running the Resource Explorer.
·         SMSAdminUI.log - Records the local Configuration Manager 2007 console tasks when you connect to Configuration Manager 2007 sites.
Management Point Log Files
·         MP_Ddr.log - Records the conversion of XML.ddr records from clients, and copies them to the site server.
·         MP_GetAuth.log - Records the status of the site management points.
·         MP_GetPolicy.log - Records policy information.
·         MP_Hinv.log - Converts XML hardware inventory records from clients and copies the files to the site server.
·         MP_Location.log - Records location manager tasks.
·         MP_Policy.log - Records policy communication.
·         MP_Relay.log - Copies files that are collected from the client.
·         MP_Retry.log - Records the hardware inventory retry processes.
·         MP_Sinv.log - Converts XML hardware inventory records from clients and copies them to the site server.
·         MP_Status.log - Converts XML.svf status message files from clients and copies them to the site server.

Operating System Deployment Log Files
·         CCMSetup.log - Provides information about client-based operating system actions.
·         CreateTSMedia.log - Provides information about task sequence media when it is created. This log is generated on the computer running the Configuration Manager 2007 administrator console.
·         DriverCatalog.log - Provides information about device drivers that have been imported into the driver catalog.
·         MP_ClientIDManager.log - Provides information about the Configuration Manager 2007 management point when it responds to Configuration Manager 2007 client ID requests from boot media or PXE. This log is generated on the Configuration Manager 2007 management point.
·         MP_DriverManager.log - Provides information about the Configuration Manager 2007 management point when it responds to a request from the Auto Apply Driver task sequence action. This log is generated on the Configuration Manager 2007 management point.
·         MP_Location.log - Provides information about the Configuration Manager 2007 management point when it responds to request state store or release state store requests from the state migration point. This log is generated on the Configuration Manager 2007 management point.
·         Pxecontrol.log - Provides information about the PXE Control Manager.
·         PXEMsi.log - Provides information about the PXE service point and is generated when the PXE service point site server has been created.
·         PXESetup.log - Provides information about the PXE service point and is generated when the PXE service point site server has been created.
·         Setupact.log Setupapi.log Setuperr.log Provide information about Windows Sysprep and setup logs.
·         SmpIsapi.log - Provides information about the state migration point Configuration Manager 2007 client request responses.
·         Smpmgr.log - Provides information about the results of state migration point health checks and configuration changes.
·         SmpMSI.log - Provides information about the state migration point and is generated when the state migration point site server has been created.
·         Smsprov.log - Provides information about the SMS provider.
·         Smspxe.log - Provides information about the Configuration Manager 2007 PXE service point.
·         SMSSMPSetup.log - Provides information about the state migration point and is generated when the state migration point site server has been created.
·         Smsts.log - General location for all operating system deployment and task sequence log events.
·         TaskSequenceProvider.log - Provides information about task sequences when they are imported, exported, or edited.
·         USMT Log loadstate.log - Provides information about the User State Migration Tool (USMT) regarding the restore of user state data.
·         USMT Log scanstate.log - Provides information about the USMT regarding the capture of user state data.


Discovery
·         adsgdis.log - Records Active Directory Security Group Discovery actions.
·         adsysdis.log - Records Active Directory System Discovery actions.
·         adusrdis.log - Records Active Directory User Discovery actions.
·         ADForestDisc.Log - Records Active Directory Forest Discovery actions.
·         ddm.log - Records activities of the discovery data manager.
·         netdisc.log - Records Network Discovery actions.
Inventory
·         dataldr.log - Records information about the processing of Management
                        Information Format (MIF) files and hardware inventory in the Configuration
                       Manager database.
·         invproc.log - Records the forwarding of MIF files from secondary site to its
                     parent site.
·         sinvproc.log - Records information about the processing of software inventory
               data to the site database.
Reporting
·         srsrp.log - Records information about the activity and status of the
reporting point.
·         srsrpMSI.log - Records detailed results of the reporting point installation
                        process from the MSI output.
·         srsrpsetup.log - Records results of the reporting point installation process.

 
Site to Site Communication Logs
·         despool.log - Records incoming site-to-site communication transfers.
·         hman.log -  hman.log - Records information about site configuration changes, and the publishing of site information in Active Directory Domain Services.
·         invproc.log - Records the forwarding of MIF files from a secondary site to its parent site.
·         PkgXferMgr.log - Records the actions of the SMS Executive component that is responsible for sending content from a primary site to a remote distribution point.
·         rcmctrl.log - Records the activities of database replication between sites in the hierarchy.
·         replmgr.log - Records the replication of files between the site server components and the Scheduler component.
·         Sched.log - Records details about site-to-site job and package replication.
·         sender.log - Records the files that transfer by file-based replication between sites.



SCCM SQL Query to get Bit-locker Recovery Key

  SELECT cm.Name, ck.RecoveryKeyId, cv.VolumeGuid, cvt.TypeName AS 'Volume Type', RecoveryAndHardwareCore.DecryptString(ck...