WSUS Tools – Cleanup, Status and Cancelling Unapproved Downloads
Written in 2008 for the Windows versions of the time. Check that the tool or steps still suit your environment before using them.
Most WSUS housekeeping is done by clicking through the console, which is fine once and tedious every month. Between 2008 and 2010 I wrote three small tools that do the common jobs from the command line, so they can run from scheduled tasks and monitoring scripts. They were originally three separate posts; this guide brings them together.
Tool | What it does | Runs against |
|---|---|---|
WSUS_Cleanup | Runs the Server Cleanup Wizard tasks you choose | The local WSUS server |
WSUS_Cancel_Unapproved_Downloads | Cancels downloads of every update that is not approved | The local WSUS server |
WSUS_Get_Status | Reports sync result and download progress | A remote WSUS server |
Prerequisites
- Microsoft.UpdateServices.Administration.dll in the path, or in the same folder as the tool. It is installed with the WSUS administration console.
- An account with WSUS administrator rights on the server.
- Run WSUS_Cleanup and WSUS_Cancel_Unapproved_Downloads on the WSUS server itself.
1. WSUS_Cleanup: Server Cleanup from the Command Line
WSUS_Cleanup performs the same tasks as the Server Cleanup Wizard. Pass one or more of these codes to choose what it does:
Code | Cleanup task |
|---|---|
COC | CleanupObsoleteComputers |
COU | CleanupObsoleteUpdates |
CUCF | CleanupUnneededContentFiles |
CU | CompressUpdates |
DEU | DeclineExpiredUpdates |
DSU | DeclineSupersededUpdates |
For example, to remove obsolete computers and updates, delete unneeded content files and decline superseded updates:
WSUS_Cleanup.exe COC COU CUCF DSUIt prints "Working..." and then "Done". Without a valid code it shows the list above.
Download: WSUS_Cleanup.zip
2. WSUS_Cancel_Unapproved_Downloads: Stop Downloading Updates You Did Not Approve
If update files are downloaded before approval, WSUS can fill its content folder with updates you will never deploy. WSUS_Cancel_Unapproved_Downloads goes through every update on the server and cancels the download of each one that is not approved, listing each one it cancels. It takes no parameters:
WSUS_Cancel_Unapproved_Downloads.exeDownload: WSUS_Cancel_Unapproved_Downloads.zip
3. WSUS_Get_Status: Check a Remote WSUS Server
WSUS_Get_Status connects to a WSUS server and prints one tab-separated line, which makes it easy to collect from several servers into a log or spreadsheet:
WSUS_Get_Status.exe SERVERNAME USESECURECONNECTION PORT
WSUS_Get_Status.exe WSUS01 False 8530USESECURECONNECTION is True or False (SSL), and PORT is the port WSUS listens on, such as 8530 (or 8531 with SSL).
Column | Value |
|---|---|
1 | Server name |
2 | Upstream server, or "Internet" when it syncs from Microsoft Update |
3 | Updates still needing files (UpdatesNeedingFilesCount) |
4 | Bytes downloaded |
5 | Total bytes to download |
6 | Last sync result: Succeeded, Failed, Canceled, NeverRun or Unknown |
7 | Time of the check |
If the server cannot be reached, every value after the server name is "Unknown".
Note: when the server syncs from Microsoft Update, there is no tab between the server name and "Internet", so split that line on the server name first.
The 2010 update added the last sync result (column 6).
Download: WSUS_Get_Status.zip
Closing
These tools were written for the WSUS versions of the time and use the WSUS administration API directly, so they need the console's DLL rather than the newer UpdateServices PowerShell module. If you are already on PowerShell, Invoke-WsusServerCleanup covers what WSUS_Cleanup does.
No comments yet
Comments are moderated and appear once approved.