Free Tools, Windows

WSUS Tools – Cleanup, Status and Cancelling Unapproved Downloads

Written in 2008 for the Windows versions of the time. Check that the tool or steps still suit your environment before using them.

Most WSUS housekeeping is done by clicking through the console, which is fine once and tedious every month. Between 2008 and 2010 I wrote three small tools that do the common jobs from the command line, so they can run from scheduled tasks and monitoring scripts. They were originally three separate posts; this guide brings them together.

Tool

What it does

Runs against

WSUS_Cleanup

Runs the Server Cleanup Wizard tasks you choose

The local WSUS server

WSUS_Cancel_Unapproved_Downloads

Cancels downloads of every update that is not approved

The local WSUS server

WSUS_Get_Status

Reports sync result and download progress

A remote WSUS server

Prerequisites

  • Microsoft.UpdateServices.Administration.dll in the path, or in the same folder as the tool. It is installed with the WSUS administration console.
  • An account with WSUS administrator rights on the server.
  • Run WSUS_Cleanup and WSUS_Cancel_Unapproved_Downloads on the WSUS server itself.

1. WSUS_Cleanup: Server Cleanup from the Command Line

WSUS_Cleanup performs the same tasks as the Server Cleanup Wizard. Pass one or more of these codes to choose what it does:

Code

Cleanup task

COC

CleanupObsoleteComputers

COU

CleanupObsoleteUpdates

CUCF

CleanupUnneededContentFiles

CU

CompressUpdates

DEU

DeclineExpiredUpdates

DSU

DeclineSupersededUpdates

For example, to remove obsolete computers and updates, delete unneeded content files and decline superseded updates:

WSUS_Cleanup.exe COC COU CUCF DSU

It prints "Working..." and then "Done". Without a valid code it shows the list above.

Download: WSUS_Cleanup.zip

2. WSUS_Cancel_Unapproved_Downloads: Stop Downloading Updates You Did Not Approve

If update files are downloaded before approval, WSUS can fill its content folder with updates you will never deploy. WSUS_Cancel_Unapproved_Downloads goes through every update on the server and cancels the download of each one that is not approved, listing each one it cancels. It takes no parameters:

WSUS_Cancel_Unapproved_Downloads.exe

Download: WSUS_Cancel_Unapproved_Downloads.zip

3. WSUS_Get_Status: Check a Remote WSUS Server

WSUS_Get_Status connects to a WSUS server and prints one tab-separated line, which makes it easy to collect from several servers into a log or spreadsheet:

WSUS_Get_Status.exe SERVERNAME USESECURECONNECTION PORT
WSUS_Get_Status.exe WSUS01 False 8530

USESECURECONNECTION is True or False (SSL), and PORT is the port WSUS listens on, such as 8530 (or 8531 with SSL).

Column

Value

1

Server name

2

Upstream server, or "Internet" when it syncs from Microsoft Update

3

Updates still needing files (UpdatesNeedingFilesCount)

4

Bytes downloaded

5

Total bytes to download

6

Last sync result: Succeeded, Failed, Canceled, NeverRun or Unknown

7

Time of the check

If the server cannot be reached, every value after the server name is "Unknown".

Note: when the server syncs from Microsoft Update, there is no tab between the server name and "Internet", so split that line on the server name first.

The 2010 update added the last sync result (column 6).

Download: WSUS_Get_Status.zip

Closing

These tools were written for the WSUS versions of the time and use the WSUS administration API directly, so they need the console's DLL rather than the newer UpdateServices PowerShell module. If you are already on PowerShell, Invoke-WsusServerCleanup covers what WSUS_Cleanup does.

Posted on

Tagged Tools

No comments yet

Comments are moderated and appear once approved.