3 Replies Latest reply on Mar 16, 2016 2:40 PM by cwinning

    Patch Baseline

    Thom.Turner Rookie

      Hello,

       

      This has been partially answered in other posts that I've seen so apologies if this is a repeat post.

       

      My scenario

      • A group of application servers are scheduled to be patched over several weekends.
      • Its important that all servers receive the same patches to ensure consistent.

       

      What is the best way to ensure that the servers patched in week 3 don't have new patches (patches Tuesday releases etc) applied?

       

      Should I schedule a scan every Wednesday after patch Tuesday so I would know all my domains missing patches?

      Then create a new Patch Group to include all patches on the Wednesday after patch Tuesday?

      Then create a new Patch Scan template and add this group in as a baseline?

       

      Will all the potential patches be in this group?

       

      If this is the recommended method can this be automated so that Shavlik creates a patch Tuesday Patch Group every month?

       

      Would be be better for me to exclude any patches from date x onwards?

       

      Thanks,

      Thom

        • 1. Re: Patch Baseline
          cwinning CommunityTeam

          Thom,

           

          You will want to create and use a baseline to prevent newer patches from scanned for and deployed.  There are no automated method of getting this done so you will need to manually add the patches to the Patch Group each month once they are released.  You use a lot of automation when be this specific in regards to which patches are scanned for and deployed.

           

          I would suggest scheduler a scan only WUScan just so you know what is missing on your servers.  Too much filtering in scans may hide potential needed patches from being applied so it's prudent to spot check from time to time.

           

          Thanks,

          Charles

          • 2. Re: Patch Baseline
            Thom.Turner Rookie

            Hi Charles.

             

            That's for the reply.

            Just to confirm:

            • I will schedule a domain scan once a month.
            • Create a new Patch group called MS Month Year
            • Then create a new template and add this patch Group in as a baseline.

             

            Thanks again,

            Thom

            • 3. Re: Patch Baseline
              cwinning CommunityTeam

              Hello,

               

              You can create a new Scan Template and Patch Group each month or you can keep adding to the previous one.  Either method would work, use what ever meets your need better.  I would suggest keep adding the newer patches to the same Patch Group each month.

               

              Thanks,

              Charles