* SCCM is a beast in itself. It's client has so many components that even if 1 Component is not working,it can cause issues
* Log files are the heart of troubleshooting for SCCM.You have to know which log file to read in which order for effective troubleshooting
* All SCCM log files are in location C:\Windowds\ccm\logs folder
* For patching issues follow the following order for troubleshooting.
*First step is to see whether patches are getting download to the client. The patches once downloaded are stored in ccmcache folder.
*This folder is in C:\windows\ccmcache
*If patches are not downloaded in this folder then you have problem with client not able to download the patches from WSUS server.
* You should immediately look for log called wuahandler.log
*Look for errors in this log most likely you will see error connecting to WSUS server.
* Generally the easiest troubleshooting step I do if I see this error only on few clients is to uninstall and reinstall the client from the
* Mostly this should resolve if there is client issue. . I suggest doing the install from SCCM console and choose the location for the source to I still from site location.
Showing posts with label Issues. Show all posts
Showing posts with label Issues. Show all posts
Saturday, 8 September 2018
SCCM client log and troubleshooting for patching
Saturday, 15 October 2016
SCCM 2012 R2 Log File for Windows Update Agent and WSUS Server issues
SCCM 2012 R2 Log File for Windows Update Agent and WSUS Server issues
Windows Update Agent
The following table lists the log files that contain information related to the Windows Update Agent.
Log name | Description | Computer with log file |
|---|---|---|
WindowsUpdate.log | Records details about when the Windows Update Agent connects to the WSUS server and retrieves the software updates for compliance assessment and whether there are updates to the agent components. | Client |
WSUS Server
The following table lists the log files that contain information related to the WSUS server.
Log name | Description | Computer with log file |
|---|---|---|
Change.log | Records details about the WSUS server database information that has changed. | WSUS server |
SoftwareDistribution.log | Records details about the software updates that are synchronized from the configured update source to the WSUS server database. | WSUS server |
SCCM 2012 R2 Log File for Microsoft Intune Connector issues
SCCM 2012 R2 Log File for Microsoft Intune Connector issues
Microsoft Intune Connector
The following table lists the log files that contain information related to the Microsoft Intune connector.
Log name | Description | Computer with log file |
|---|---|---|
CertMgr.log | Records certificate and proxy account information. | Site server |
CollEval.log | Records details about when collections are created, changed, and deleted by the Collection Evaluator. | Primary site and central administration site |
Cloudusersync.log | Records license enablement for users. | Computer with the Intune connector |
Dataldr.log | Records information about the processing of MIF files. | Site server |
ddm.log | Records activities of the discovery data manager. | Site server |
Distmgr.log | Records details about content distribution requests. | Top-level site server |
Dmpdownloader.log | Records details on downloads from Microsoft Intune. | Computer with the Intune connector |
Dmpuploader.log | Records details for uploading database changes to Microsoft Intune. | Computer with the Intune connector |
hman.log | Records information about message forwarding. | Site server |
objreplmgr.log | Records the processing of policy and assignment. | Primary site server |
PolicyPV.log | Records policy generation of all policies. | Site server |
outgoingcontentmanager.log | Records content uploaded to Microsoft Intune. | Computer with the Intune connector |
Sitecomp.log | Records details of connector role installation. | Site server |
SmsAdminUI.log | Records Configuration Manager console activity. | Computer that runs the Configuration Manager console |
Smsprov.log | Records activities performed by the SMS Provider. Configuration Manager console activities use the SMS Provider. | Computer with the SMS Provider |
SrvBoot.log | Records details about the Intune connector installer service. | Computer with the Intune connector |
Statesys.log | Records the processing of mobile device management messages. | Primary site and central administration site |
SCCM 2012 R2 Log File for Software Updates and Network Access Protection issues
Software Updates and Network Access Protection
The following table lists the log files that contain information related to software updates and Network Access Protection.
Log name | Description | Computer with log file |
|---|---|---|
ccmcca.log | Records details about the processing of compliance evaluation based on Configuration Manager NAP policy processing, and contains the processing of remediation for each software update required for compliance. | Client |
ccmperf.log | Records activities related to the maintenance and capture of data related to client performance counters. | Client |
PatchDownloader.log | Records details about the process of downloading software updates from the update source to the download destination on the site server. | The computer hosting the Configuration Manager console from which downloads are initiated |
PolicyEvaluator.log | Records details about the evaluation of policies on client computers, including policies from software updates. | Client |
RebootCoordinator.log | Records details about the coordination of system restarts on client computers after software update installations. | Client |
ScanAgent.log | Records details about scan requests for software updates, the WSUS location, and related actions. | Client |
SdmAgent.log | Records details about tracking of remediation and compliance. However, the software updates log file, Updateshandler.log, provides more informative details about installing the software updates required for compliance. This log file is shared with compliance settings. | Client |
ServiceWindowManager.log | Records details about the evaluation of maintenance windows. | Client |
smssha.log | The main log file for the Configuration Manager Network Access Protection client and it contains a merged statement of health information from the two Configuration Manager components: location services (LS) and the configuration compliance agent (CCA). This log file also contains information about the interactions between the Configuration Manager System Health Agent and the operating system NAP agent, and also between the Configuration Manager System Health Agent and both the configuration compliance agent and the location services. It provides information about whether the NAP agent successfully initialized, the statement of health data, and the statement of health response. | Client |
Smsshv.log | This is the main log file for the System Health Validator point and records the basic operations of the System Health Validator service, such as the initialization progress. | Site system server |
Smsshvadcacheclient.log | Records details about the retrieval of Configuration Manager health state references from Active Directory Domain Services. | Site system server |
SmsSHVCacheStore.log | Records details about the cache store used to hold the Configuration Manager NAP health state references retrieved from Active Directory Domain Services, such as reading from the store and purging entries from the local cache store file. The cache store is not configurable. | Site system server |
smsSHVQuarValidator.log | Records client statement of health information and processing operations. To obtain full information, change the registry key LogLevel from 1 to 0 in the following location:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMSSHV\Logging\@GLOBAL | Site system server |
smsshvregistrysettings.log | Records any dynamic change to the System Health Validator component configuration while the service is running. | Site system server |
SMSSHVSetup.log | Records the success or failure (with failure reason) of installing the System Health Validator point. | Site system server |
SmsWusHandler.log | Records details about the scan process for the Inventory Tool for Microsoft Updates. | Client |
StateMessage.log | Records details about software updates state messages that are created and sent to the management point. | Client |
SUPSetup.log | Records details about the software update point installation. When the software update point installation completes, Installation was successful is written to this log file. | Site system server |
UpdatesDeployment.log | Records details about deployments on the client, including software update activation, evaluation, and enforcement. Verbose logging shows additional information about the interaction with the client user interface. | Client |
UpdatesHandler.log | Records details about software update compliance scanning and about the download and installation of software updates on the client. | Client |
UpdatesStore.log | Records details about compliance status for the software updates that were assessed during the compliance scan cycle. | Client |
WCM.log | Records details about software update point configurations and connections to the Windows Server Update Services (WSUS) server for subscribed update categories, classifications, and languages. | Site server |
WSUSCtrl.log | Records details about the configuration, database connectivity, and health of the WSUS server for the site. | Site system server |
wsyncmgr.log | Records details about the software updates synchronization process. | Site server |
WUAHandler.log | Records details about the Windows Update Agent on the client when it searches for software updates. | Client |
SCCM 2012 R2 Log File for SCCM Role-Based Administration ISSUES
SCCM 2012 R2 Log File for SCCM Role-Based Administration ISSUES
Role-Based Administration
The following table lists the log files that contain information related to managing role-based administration.
Log name | Description | Computer with log file |
|---|---|---|
hman.log | Records information about site configuration changes, and the publishing of site information to Active Directory Domain Services. | Site server |
SMSProv.log | Records WMI provider access to the site database. | Computer with the SMS Provider |
SCCM 2012 R2 Log File for SCCM Reporting issues
SCCM 2012 R2 Log File for SCCM Reporting issues
Reporting
The following table lists the Configuration Manager log files that contain information related to reporting.
Log name | Description | Computer with log file |
|---|---|---|
srsrp.log | Records information about the activity and status of the reporting services point. | Site system server |
srsrpMSI.log | Records detailed results of the reporting services point installation process from the MSI output. | Site system server |
srsrpsetup.log | Records results of the reporting services point installation process. | Site system server |
SCCM 2012 R2 Log Files for SCCM Exchange server connector issues
SCCM 2012 R2 Log Files for SCCM Exchange server connector issues
Exchange Server Connector
The following table lists logs that contain information related to the Exchange Server connector.
Log name | Description | Computer with log file |
|---|---|---|
easdisc.log | Records the activities and the status of the Exchange Server connector. | Site server |
SCCM 2012 R2 Log File for Mobile Device Issues
SCCM 2012 R2 Log File for Mobile Device Issues
Mobile Devices
The following sections list the log files that contain information related to managing mobile devices .
Enrollment
The following table lists logs that contain information related to mobile device enrollment.
Log name | Description | Computer with log file |
|---|---|---|
DMPRP.log | Records communication between management points that are enabled for mobile devices and the management point endpoints. | Site system server |
dmpmsi.log | Records the Windows Installer data for the configuration of a management point that is enabled for mobile devices. | Site system server |
DMPSetup.log | Records the configuration of the management point when it is enabled for mobile devices. | Site system server |
enrollsrvMSI.log | Records the Windows Installer data for the configuration of an enrollment point. | Site system server |
enrollmentweb.log | Records communication between mobile devices and the enrollment proxy point. | Site system server |
enrollwebMSI.log | Records the Windows Installer data for the configuration of an enrollment proxy point. | Site system server |
enrollmentservice.log | Records communication between an enrollment proxy point and an enrollment point. | Site system server |
SMS_DM.log | Records communication between mobile devices, Mac computers and the management point that is enabled for mobile devices and Mac computers. | Site system server |
SCCM 2012 R2 Log File for SCCM Inventory issues
SCCM 2012 R2 Log File for SCCM Inventory issues
Inventory
The following table lists the log files that contain information related to processing inventory data.
Log name | Description | Computer with log file |
|---|---|---|
dataldr.log | Records information about the processing of Management Information Format (MIF) files and hardware inventory in the Configuration Manager database. | Site server |
invproc.log | Records the forwarding of MIF files from a secondary site to its parent site. | Secondary site server |
sinvproc.log | Records information about the processing of software inventory data to the site database. | Site server |
SCCM 2012 R2 Log File for SCCM Discovery issues
SCCM 2012 R2 Log File for SCCM Discovery issues
Discovery
he following table lists the log files that contain information related to Discovery.
Log name | Description | Computer with log file |
|---|---|---|
adsgdis.log | Records Active Directory Security Group Discovery actions. | Site server |
adsysdis.log | Records Active Directory System Discovery actions. | Site server |
adusrdis.log | Records Active Directory User Discovery actions. | Site server |
ADForestDisc.Log | Records Active Directory Forest Discovery actions. | Site server |
ddm.log | Records activities of the discovery data manager. | Site server |
InventoryAgent.log | Records activities of hardware inventory, software inventory, and heartbeat discovery actions on the client. | Client |
netdisc.log | Records Network Discovery actions. | Site server |
SCCM 2012 R2 Log File for Content Management Issues
SCCM 2012 R2 Log File for Content Management Issues
Content Management
The following table lists the log files that contain information related to content management.
Log name | Description | Computer with log file |
|---|---|---|
For System Center 2012 Configuration Manager SP1 and later: CloudDP-<guid>.log | Records details for a specific cloud-based distribution point, including information about storage and content access. | Site system server |
CloudMgr.log | Records details about the provisioning of content, collecting storage and bandwidth statistics, and administrator initiated actions to stop or start the cloud service that runs a cloud-based distribution point. | Site system server |
For System Center 2012 Configuration Manager SP1 and later: DataTransferService.log | Records all BITS communication for policy or package access. This log is also used for content management by pull-distribution points. | A computer that is configured as a pull-distribution point |
For System Center 2012 Configuration Manager SP1 and later: PullDP.log | Records details about content that the pull-distribution point transfers from source distribution points. | A computer that is configured as a pull-distribution point |
PrestageContent.log | Records the details about the use of the ExtractContent.exe tool on a remote prestaged distribution point. This tool extracts content that has been exported to a file. | Site system role |
SMSdpmon.log | Records details about the distribution point health monitoring scheduled task that are configured on a distribution point. | Site system role |
smsdpprov.log | Records details about the extraction of compressed files received from a primary site. This log is generated by the WMI Provider of the remote distribution point. | A distribution point computer that is not co-located with the site server. |
SCCM 2012 R2 Compliance Settings and Computer resource Access issues
SCCM 2012 R2 Compliance Settings and Computer resource Access issues
Compliance Settings and Company Resource Access
The following table lists the log files that contain information related to compliance settings and company resource access.
Log name | Description | Computer with log file |
|---|---|---|
CIAgent.log | Records details about the process of remediation and compliance for compliance settings, software updates, and application management. | Client |
CITaskManager.log | Records information about configuration item task scheduling. | Client |
DCMAgent.log | Records high-level information about the evaluation, conflict reporting, and remediation of configuration items and applications. | Client |
DCMReporting.log | Records information about reporting policy platform results into state messages for configuration items. | Client |
DcmWmiProvider.log | Records information about reading configuration item synclets from Windows Management Instrumentation (WMI). | Client |
SCCM 2012 R2 Log File for Client Notification issues
SCCM 2012 R2 Log File for Client Notification issues
Client Notification
The following table lists the log files that contain information related to client notification.
Log name | Description | Computer with log file |
|---|---|---|
bgbmgr.log | Records details about the activities of the site server relating to client notification tasks and processing online and task status files. | Site server |
BGBServer.log | Records the activities of the notification server such as client-server communications and pushing tasks to clients. Also records information about online and task status files generation to be sent to the site server. | Management point |
BgbSetup.log | Records the activities of the notification server installation wrapper process during installation and uninstall. | Management point |
bgbisapiMSI.log | Records details about the notification server installation and uninstall. | Management point |
BgbHttpProxy.log | Records the activities of the notification HTTP proxy as it relays the messages of clients using HTTP to and from the notification server. | Client |
CcmNotificationAgent.log | Records the activities of the notification agent such as client-server communication and information about tasks received and dispatched to other client agents. | Client |
Thursday, 31 March 2016
Known Issues and Troubleshooting for Windows Server Base OS Management pack
Known Issues and Troubleshooting for Windows Server Base OS Management pack
- Disk Partitions Which Correspond to Mounted Disks Are Not Monitored
Issue: Disk partition discovery is not enabled by default, but when
enabled, disk partitions that correspond to mounted disks cannot be monitored
properly and will show up as “Not Monitored” in the Operations Console.
Management is still provided by way of other means in this management pack, but
the disk partition perspective will not work in these instances.
Workaround: There is no workaround currently available.
- The “Core Windows Services Rollup” Monitor for Windows Server 2008 Includes Services That It Should Not
Issue: The Core Windows Services Rollup monitoring that exists in all
server operating system management packs aggregates the state of a number of
monitors that are watching the state of various “core services” and will change
state if any one of those services is not running. The Windows Server 2008
version of this monitor includes a monitor for the “Computer Browser Service
Health,” which is not accurate because the service is no longer required for
the Windows Server 2008 operating system to function properly.
Workaround: The monitor can be safely ignored, but it can also be disabled by
overriding it.
- Remote Desktop (Admin) Not Always Accessible
Issue: There are times when Remote Desktop (Admin) is not accessible.
Workaround: The new Remote Desktop (Admin) functionality of Windows
Server 2008 is supported by way of the /admin switch. However, it is
available only in Windows Server 2008 and the Windows Vista operating
system with SP1.
- The Console Session Does Not Work in Windows Server 2008
Issue: Attempts to use the /console switch do not work properly.
Workaround: The console session no longer exists in Windows Server 2008. Use of
the /console switch will be ignored, and the behavior is the same as a simple
Remote Desktop task.
- Behavior for Accessing the Console Session of Windows Server 2003 Has Changed
Issue: There is a change in behavior for accessing the console session of
Windows Server 2003.
Workaround: For the Windows XP operating system with SP1 or earlier and
Windows Vista, use the Remote Desktop (Console) task in Windows
Server 2003. Remote Desktop (Admin) will cause an error dialog. For
Windows Vista with SP1, use the Remote Desktop (Admin) task in Windows
Server 2008. Remote Desktop (Console) will work as the Remote Desktop task
without any notice.
- SUBST Drive Mappings Are Not Supported by Logical Disk Monitoring
Issue: There is a command-line tool (SUBST.exe) that can be used to associate
a path (such as c:\windows\system32) with a drive letter (such as D:\). Because
these mappings are exposed in WMI, logical disk monitoring discovers them and
attempts to monitor them as such, but will subsequently generate errors.
Workaround: There is no workaround currently available, and this configuration
is not supported.
Known Issues with Localized Versions of the Management Pack:
- Object discoveries scoped to Windows Server 2008 Computer and Windows Server 2008 Operating System may not display correctly in the Authoring pane.
- Some instances of localized display strings may not display correctly in the Operations console.
Known Issue: Cluster Disks Managed by
Third-Party Software are Not Monitored
- Issue: If the Cluster disks are managed by third party software, and they change the resource type to anything other than “Physical Disk”, these disks will be discovered but we do not provide monitoring for these.
- Workaround: There is no workaround currently available. In future, we will be removing discovery for these too.
Known Issue: PowerShell in 2012 MP failed if
.NET is uninstalled from Core OS agent by user
- Issue: .NET 4.5 and PowerShell are installed by default on Core OS and PowerShell depends on .NET, if they are uninstalled from Core OS agent by user, some workflows depending on PowerShell in 2012 MP will be failed.
- Workaround: Install .NET Framework 4.5 and PowerShell on Core Operating System.
Subscribe to:
Posts (Atom)