Event ID: 364 - Content file download failed. Reason: The server does not support the necessary HTTP protocol. Background Intelligent Transfer Service (BITS) requires that the server support the Range protocol header. The Windows Server Update Services console crashes when browsing for updates Content provided by Microsoft Applies to: Windows Server Update Services 3.0 Service Pack 2.
Monitor unlimited number of servers
Filter log events
Create email and web-based reports
Direct access to Microsoft articles
Customized keywords for major search engines
Access to premium content
Event ID: 10032 Source: WindowsServerUpdateServices
To show all the BITS jobs execute:
Bitsadmin /List /AllUsers
If list is long and many jobs are suspended, maybe proxy settings for Bits Service are not set correct. Make sure that BITS is running under LocalSystem account.
To validate correct settings, execute:
bitsadmin /Info {oneofthesejobs} /Verbose
Output shows the 'Owner', 'Proxy List' and 'Proxy Bypass List'. Your proxy should be listed. If not, the workaround is launching IE as LocalSystem using:
psexec -s -i 'C:Program FilesInternet Exploreriexplore.exe'
and set proxy manually, or:
psexec -s 'netsh winhttp set proxy {proxy}:{port}'
Open a command window.
Type sc config bits start= auto
Type net stop bits && net start bits
Type net stop wsusservice && net start wsusservice
Start WSUS 3.0: Click Start, click Administrative Tools, then click Microsoft Windows Server Update Services v3.0.
Click Synchronization Results.
In the Action pane, click Synchronize Now.
Verify (Look for the corresponding error event_
Open a command window.
Type cd <WSUSInstallDir>Tools
Type wsusutil checkhealth
Review the Application log for the most recent events from source Windows Server Update Services and event id 10030.
1. 'Users' or 'NT AuthorityNetwork Service' account: 'Read' on root folder for drive where WSUS content directory resides.
2. 'NT AuthorityNetwork Service' account: 'Full Control' for:
- WSUS content directory (WSUSWsusContent)
- %windir%Microsoft.NETFrameworkv2.0.50727Temporary ASP.NET Files
- %windir%Temp
Event Id 364 Windows Server Update Services
Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.
Windows Update Event Id 20
Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.