Wsus - Update to enable WSUS support for Windows 10 feature upgrades KB3095113

This update enables Windows Server Update Services (WSUS) on a Windows Server 2012-based or a Windows Server 2012 R2-based server to sync and distribute feature upgrades for Windows 10. This update is not required to enable WSUS to sync and distribute servicing updates for Windows 10.

Important This update must be installed before you sync the upgrades classification. If the update is not installed when the upgrades classification is enabled, WSUS will see the Windows 10 build 1511 feature upgrade even if it can’t properly download and deploy the associated packages. If you try to sync any upgrades without having first installed KB 3095113, you will populate the SUSDB with unusable data that must be cleared before upgrades can be properly distributed. This situation is recoverable but the process is nontrivial and can be avoided altogether if you make sure to install the update before enabling sync of upgrades. If you have encountered this issue, refer to the following article:
For more information about Windows 10 servicing and how feature upgrades and servicing updates differ, see the following TechNet topic:
This update also fixes an issue in which Windows 10-based computers are displayed as "Windows Vista" on Windows Server 2012 R2 or Windows Server 2012.

https://support.microsoft.com/en-us/kb/3095113

Sophos - How to enable webcontrol verbose logging

-----------------------------------------
Article ID:116769
Linked Article:How to enable Sophos Web Intelligence (Web Protection feature) and Web Control logging
-----------------------------------------

What To Do

Web Filtering logging

By default only blocked URLs are logged to the default SAV.txt log. 
The following information is logged in SAV.txt:
  • Each blocked URL
  • The referrer URL
  • The name of the user
  • The Sophos Labs reason code
It is however possible to enable more verbose logging which provides information on multiple components of SAV to do with Web Filtering. To enable these logs, follow these instructions:
  1. Open Regedit and navigate to the following location:
    32-bit:
    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Web Intelligence\
    64-bit:
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Web Intelligence\
  2. Add a new DWORD named LogLevel
  3. Set the value to 3
  4. Open the service manager (services.msc) and restart the Sophos Web Intelligence service to start logging.

Values

1 - Information
2 - Trace
3 - Debug

Logs written

C:\WINDOWS\Temp\swisdiag.log
C:\WINDOWS\Temp\swifdiag.log
%TEMP%\swifdiag.log

Web Control logging

Verbose logging for Web Control can be achieved with the following instructions:
  1. Open Regedit and navigate to the following location:
    32-bit:
    HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Web Intelligence\
    64-bit:
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Web Intelligence\
  2. Add a new DWORD named LogLevel
  3. Set the value to 3
  4. Navigate to the following location:
  5. 32-bit: HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Web Intelligence\Web Control\
    64-bit: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Web Intelligence\Web Control\
  6. Add a new DWORD named LogLevel
  7. Set the value to 3
  8. Open the service manager (services.msc) and restart the Sophos Web Control and Sophos Web Intelligence services to start logging.

Values

1 - Information
2 - Trace
3 - Debug

Logs written

C:\WINDOWS\Temp\swc_diag.log
C:\WINDOWS\Temp\swc_messaging.log
C:\WINDOWS\Temp\swc_rms_diag.log
C:\WINDOWS\Temp\swifdiag.log
C:\WINDOWS\Temp\swisdiag.log
%TEMP%\swc_messaging.log
%TEMP%\swifdiag.log

Disabling Logging

  1. Open Regedit and navigate to the following location:
    • 32-bit
      • HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Web Intelligence\Web Control\
      • HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Web Intelligence\
    • 64-bit
      • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Web Intelligence\Web Control\
      • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Sophos\Web Intelligence\
  2. Change the value in LogLevel to 0 at each location.

Note: Restarting the service(s) isn't required. If logging persists, a restart may be required. This can occur when the processes involved are not restarted with the service.

Microsoft MVA - What's New in PowerShell v5

Would you like to learn about the latest and greatest features that Microsoft has built into PowerShell Version 5? Be sure to check out this course, and get the details that can enable you to begin using these features immediately.

Explore the new features in PowerShell, including changes in security, scripting, debugging, and administration role management, along with the PowerShell Gallery, ScriptAnalyzer, and DSC. Plus, learn to install modules, implement the Wait Debugger, look at Just Enough Administration, and much more.

1 | Introduction to PowerShell v5
Get an overview of the new features in PowerShell v5.
2 | Package Management
Learn what's new with package management in PowerShell v5
3 | PowerShell v5 Security
Get the details on what's new with security in PowerShell v5.

Tips - Msdt command to invoke a troubleshooting pack at the command line

Here is an interesting Microsoft article that indicvate msdt command to invoke a troubleshooting pack at the command line or as part of an automated script, and enables additional options without user input.

It can be useful to create a desktop script to be launched from end user withouth follow several click/windows before try to solve (about lan and wifi for example)


Here they are some articles:

Msdt

Troubleshooting Windows (and Dimming Your Display, too)

Powershell - Script to identify Exchange Rollup installed

Here is a script that is useful to find, in your environment Exchange server version and rollup installed to csv.

Check Exchange 2010 Rollup Version

Scripting - Monitor disk space, cpu load, memory and send html report through email

Here they are some scripts that monitor CPU, Disk Drives space and others:

1.) Powershell Script to Get CPU,Memory and C Drive utilization(Server Health Check)

a simple powershell script to get CPU Load, Memory utilization and C drive Utilization for a list of servers from a text file. So, this script takes servers from a text file and the result will be displayed in a HTML file and Sends email.


https://gallery.technet.microsoft.com/Powershell-Script-to-Get-78687c5e


https://gallery.technet.microsoft.com/scriptcenter/PowerShell-Script-Sample-f7164554

2.) Disk Space monitoring

a simple powershell script to get CPU. Memory utilization and C drive Utilization for a list of servers from a text file and the result will be displayed in a HTML file and sends email to your mailbox. I Feel It will be useful if you add this as a schedule task and run peridoically, it just reports you with the status to your email.

https://gallery.technet.microsoft.com/fd4f5235-1a80-41ed-87e2-189278fd376c

3.) PowerShell script to report free disk space on servers

script calculates free disk spaces in multiple servers (from a text file) and emails copy of csv report. The script is designed to report only servers with less than 10% free space. Customization info provided. Please rate, leave comments and ask questions.

This PowerShell script calculates free disk spaces in multiple servers and emails copy of  csv report. The script is designed to report only servers with 10% or less free space. If you wish to report all free disk spaces, please comment out the following lines in the swcript: #Where-Object {   ($_.freespace/$_.size) -le '0.1'} - This is found directly beneath the Get-WmiObject win32_logicaldisk command (Around line 50).


https://gallery.technet.microsoft.com/scriptcenter/PowerShell-Script-Sample-f7164554


4.) Monitoring and reporting free disk space and the critical services


This script is designated to collect free disk space on your logical drives and state of some Windows services using PowerShell cmdlets.Also, this script will use local or remote SMTP Server to send the report via e-mail.You can modify srvArray variable to monitor more services.


https://gallery.technet.microsoft.com/PowerShell-and-reporting-3dba70fc


5.) DiskSpace Monitoring

It's an improvement from the original Nag Pal's script


It will retrieve the letter, size, free space (GB), free space (%) from every volume on each server on the server list, and will mark in yellow if the free space is under 20% and in red if it under 10%.


The result file includes the date and also the heeder inside the file.



The improvements were made to include the date and to avoid errors where a server can’t be reached.

https://gallery.technet.microsoft.com/cc8176ab-348b-4152-b9a3-25b6ad950d3e


6.) CPU utilization and notify on a threshold breach

Here is a simple powershell script which will take a list of servers as input, monitors CPU load and sends email notifications incase of threshold breach(which is set in script). You may need to configure this script in scheduled task for continuous monitoring.

https://gallery.technet.microsoft.com/Powershell-script-to-11b10872

<------------>

Otherwise if you review this old post:

http://www.alessandromazzanti.com/2015/09/security-netrwrix-tools-auditing.html

There should be available these netwrix tools:

SYSTEMS MANAGEMENT TOOLS

Netwrix Disk Space Monitor: Be alerted in real-time via email when disk space falls below certain thresholds on one or more of your servers.
Netwrix Event Log Manager: Collect, alert and report on events from the Windows servers across your network.
Netwrix Service Monitor: Monitor services on multiple servers simultaneously and be alerted via email when one or more services stop unexpectedly. Optionally, automatically restart monitored services ensuring maximum uptime.