25-03-04 14:01
[MS Windows] Log datoteke SUS-a
piše BORIS TROJAN
Nadzor rada nadogradnje OSa preko SUSa
SUS server je web server koji simulira funkcionalnost Microsoft Windows
Update web sitea, iako ne u potpunosti. Sustav se sastoji od klijenta
(AutoUpdate clinet ili AU) i servera. U skladu s tim, postoje dve log
datoteke koje nam mogu pomoći u radu.
1. klijent log datoteka: c:\winnt\windows update.log
Ovaj log sadrži unose koji izgledaju ovako:
2003-01-25 15:50:59 23:50:59 Success IUCTL Starting
2003-01-25 15:50:59 23:50:59 Success IUCTL Downloaded iuident.cab from
http://your-sus-server to C:\Program Files\WindowsUpdate\V4
2003-01-25 15:51:00 23:51:00 Success IUENGINE Starting
2003-01-25 15:51:00 23:51:00 Success IUENGINE Determining machine
configuration
2003-01-25 15:51:00 23:51:00 Success IUENGINE Querying software update
catalog from http://your-sus-server/autoupdate/getmanifest.asp
2003-01-25 15:51:00 23:51:00 Success IUENGINE Determining machine
configuration
2003-01-25 15:51:00 23:51:00 Success IUENGINE Querying software update
catalog from http://your-sus-server/autoupdate/getmanifest.asp
2003-01-25 15:51:00 23:51:00 Success IUENGINE Determining machine configuration
2003-01-25 15:51:01 23:51:01 Success IUENGINE Querying software update
catalog from http://your-sus-server/autoupdate/getmanifest.asp
2003-01-25 15:51:01 23:51:01 Success IUENGINE Determining machine configuration
2003-01-25 15:51:02 23:51:02 Error IUENGINE Querying software update
catalog from http://your-sus-server/autoupdatedrivers/getmanifest.asp
(Error 0x801901F4)
2003-01-25 15:51:02 23:51:02 Success IUENGINE Shutting down
2003-01-25 15:51:02 23:51:02 Success IUCTL Shutting down
Ovdje su navedene informacije o uspješnim ili neuspješnim transakcijama između klijenta i vašeg SUS servera (http://vaš SUS server). Greška 801901F4 (koja se prevodi kao HTTP 404 greška) ne zahtjeva korekciju - direktorij \autoupdates nije dostupan na vašem serveru jer SUS ne podržava serviranje drivera za update.
2. server log folder: c:\winnt\system32\logfiles\w3svc1 (log datoteka IIS servisa)
sadrži niz log datoteka exYYMMDD.log čiji format ovisi o konfiguraciji vremenske zone na vašem serveru. Ovaj log sadrži unose koji tipično izgledaju ovako:
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 HEAD /iuident.cab 0301252350
200 Industry+Update+Control
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 GET /iuident.cab 0301252350
200 Industry+Update+Control
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 HEAD /selfupdate/AU/x86/XP/en/
wuaucomp.cab 0301252350 200 Industry+Update+Control
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 GET /selfupdate/AU/x86/XP/en/
wuaucomp.cab 0301252350 200 Industry+Update+Control
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 HEAD /iuident.cab 0301252350
200 Industry+Update+Control
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 GET /wutrack.bin V=1&
U=882f450045bdf949b01d3342ec0287a4&C=iu&A=n&I=&D=&P=5.1.a28.2.100.
1.0&L=en-US&S=s&E=00000000&M=&X=030125235100081 200 Industry+Update+Control
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 POST /autoupdate/getmanifest.asp
- 200 Mozilla/4.0+(compatible;+Win32;+WinHttp.WinHttpRequest.5)
2003-01-25 23:50:59 192.168.1.103 - 192.168.1.10 80 POST /autoupdate/getmanifest.asp
- 200 Mozilla/4.0+(compatible;+Win32;+WinHttp.WinHttpRequest.5)
2003-01-25 23:51:00 192.168.1.103 - 192.168.1.10 80 POST /autoupdate/getmanifest.asp
- 200 Mozilla/4.0+(compatible;+Win32;+WinHttp.WinHttpRequest.5)
2003-01-25 23:51:00 192.168.1.103 - 192.168.1.10 80 GET /wutrack.bin V=1&
U=882f450045bdf949b01d3342ec0287a4&C=au&A=d&I=&D=&P=5.1.a28.2.100.
1.0&L=en-US&S=s&E=00000000&M=items%3D0&X=030125235101440 200 Industry+Update+Control
2003-01-25 23:51:00 192.168.1.103 - 192.168.1.10 80 POST /autoupdatedrivers/getmanifest.asp
- 500 Mozilla/4.0+(compatible;+Win32;+WinHttp.WinHttpRequest.5)
Parser za ovu datoteku se nalazi na http://www.pdxconsulting.com/sus/
Napomena:
Bez obzira što se često dešava da se indikacija SUS konfiguracije klijenta dobivena kroz Group Policy izgubi na sistemu, pogled na log datoteku uvjerit će nas u suprotno - update OS-a odvija se preko SUS servera. Nadalje, greška u nenalaženju verzije drivera za update biva ispravljena na način da SUS istoimenu datoteku (getmanifest.asp) pronalazi na web serveru Microsofta:
2004-03-18 14:23:45 13:23:45 Success IUENGINE Determining machine configuration
2004-03-18 14:23:45 13:23:45 Success IUENGINE Determining machine configuration
2004-03-18 14:24:02 13:24:02 Success IUENGINE Querying software update catalog from
https://v4.windowsupdate.microsoft.com/getmanifest.asp
2004-03-18 14:24:03 13:24:03 Success IUENGINE Querying software update catalog from
https://v4.windowsupdate.microsoft.com/getmanifest.asp
2004-03-18 14:24:03 13:24:03 Success IUENGINE Querying software update catalog from
https://v4.windowsupdate.microsoft.com/getmanifest.asp
2004-03-18 14:24:05 13:24:05 Success IUENGINE Querying software update catalog from
https://v4.windowsupdate.microsoft.com/getmanifest.asp
2004-03-18 14:24:06 13:24:06 Success IUENGINE Determining machine configuration
2004-03-18 14:24:06 13:24:06 Success IUENGINE Querying software update catalog from
https://v4.windowsupdate.microsoft.com/consumerdrivers/getmanifest.asp
Izvor:
http://www.susserver.com
|