log analytics how to pull all updates installed on a server with names

%3CLINGO-SUB%20id%3D%22lingo-sub-1207534%22%20slang%3D%22en-US%22%3Elog%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207534%22%20slang%3D%22en-US%22%3E%3CP%3Ebeen%20trying%20to%20get%20a%20list%20of%20all%20the%20updates%20that%20are%20installed%20on%20a%20server%20%3F%20just%20cant%20find%20anything%20on%20it.%20im%20new%20to%20this%20so%20if%20anyone%20can%20help%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1207534%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Monitor%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3276468%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3276468%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1191822%22%20target%3D%22_blank%22%3E%40MiguelAND%3C%2FA%3E%2C%20not%20directly%2C%20I%20ended%20up%20using%20logs%20from%20an%20Elastic%20beat%20on%20the%20box%20itself%20to%20provide%20the%20information%20with%20which%20we%20could%20alert%20if%20an%20update%20was%20installed%20outside%20of%20Update%20Management.%20You%20could%20probably%20get%20the%20same%20information%20from%20the%20Windows%20Event%20Logs%20going%20into%20Log%20Analytics.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2868711%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2868711%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F889571%22%20target%3D%22_blank%22%3E%40neilashbysenior%3C%2FA%3E%26nbsp%3BDid%20you%20find%20a%20solution%20for%20this%20topic%3F%20I%20am%20experiencing%20the%20same%20issue.%20The%20idea%20is%20to%20check%20if%20certain%20KBs%20are%20installed%2C%20to%20ensure%20that%20some%20CVEs%20are%20patched...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1975288%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1975288%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F889571%22%20target%3D%22_blank%22%3E%40neilashbysenior%3C%2FA%3E%26nbsp%3B%20I%20think%20Usage%20only%20shows%20the%20required%20updates%2C%20not%20what%20is%20there.%26nbsp%3B%20%26nbsp%3BOthers%20may%20know%20more%20as%20I'm%20not%20familiar%20with%20the%20data%20itself.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1972300%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1972300%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40CliveWatson%3C%2FA%3EHi%20Clive.%20Thanks%20for%20the%20reply.%20Yes%20I%20saw%20those%20and%20they%20do%20provide%20useful%20information%20but%20from%20what%20I%20can%20see%20it%20all%20pertains%20to%20what%20Update%20Management%20did%20rather%20than%20the%20current%20status%20of%20a%20machine.%20I%20wanted%20a%20way%20to%20ascsertain%20what%20updates%2Fpackages%20were%20on%20a%20machine%20regardless%20of%20how%20they%20were%20installed%2C%20which%20I%20don't%20seem%20to%20be%20able%20to%20find.%20It%20doesn't%20look%20like%20manually%20installed%20updates%2Fpackages%20would%20be%20logged%20anywhere.%20Or%20have%20I%20missed%20the%20query%3F!%3C%2FP%3E%3CP%3ENeil.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1961599%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1961599%22%20slang%3D%22en-US%22%3EDid%20you%20look%20at%20the%20examples%3F%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fupdate-management%2Fquery-logs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fupdate-management%2Fquery-logs%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1951649%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1951649%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40CliveWatson%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Clive%2C%20I've%20got%20Update%20Management%20setup%20and%20it%20works%20in%20terms%20of%20installing%20updates.%20I%20want%20a%20way%20to%20ascertain%20what%20patches%20and%20versions%20(as%20well%20as%20packages%20with%20versions%20for%20Linux)%20are%20installed%20on%26nbsp%3B%20a%20particular%20box.%20This%20can%20then%20be%20compared%20against%20an%20external%20database%20of%20patch%20information%20to%20ascertain%20if%20any%20patches%20have%20been%20installed%20outside%20of%20the%20approval%20process.%3C%2FP%3E%3CP%3EThe%20information%20in%20Log%20Analytics%20does%20not%20appear%20to%20provide%20this%2C%20though%20I%20haven't%20worked%20much%20with%20Log%20Analytics%20so%20it's%20possible%20I%20don't%20know%20how.%20I%20have%20searched%20online%20and%20can't%20find%20the%20answer%2C%20hence%20commenting%20here.%3C%2FP%3E%3CP%3EIs%20there%20a%20way%20to%20query%20an%20API%20or%20something%20and%20get%20a%20JSON%20back%2C%20please%3F%20Or%20indeed%20go%20direct%20to%20the%20VM%20agent%3F%20Anything%20that%20shows%20that%20current%20state%20of%20the%20VM%20would%20be%20helpful%2C%20ideally%20with%20some%20audit%20information.%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3ENeil.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1213729%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1213729%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40CliveWatson%3C%2FA%3E%26nbsp%3Bthank%20you%2C%20sir!%20that%20helps%20alot%20coming%20from%20an%20MVP.%20i%20can%20take%20that%20let%20the%20boss%20know%20i%20was%20right%20the%20first%20time.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1213027%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1213027%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F573655%22%20target%3D%22_blank%22%3E%40kashifhafeez%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThat%20is%20how%20the%20agent%20works%2C%20data%20is%20from%20installation%20time.%26nbsp%3B%20If%20you%20wanted%20older%20data%20you'd%20have%20to%20use%20the%20Log%20Analytocs%20api%20to%20import%20it%2C%20but%20that's%20not%20a%20trivial%20piece%20of%20work.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1212089%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1212089%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40CliveWatson%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EThen%20you%20for%20the%20response%20Clive.%26nbsp%3B%3CBR%20%2F%3EI%20have%20a%20Windows%20and%20Linux%20OMS%20agent%20installed.%20i%20am%20able%20to%20pull%20data%20from%20Windows%20OMS%20agent%20and%20apply%20updates%20and%20see%20what%20updates%20and%20patches%20are%20missing.%26nbsp%3B%20these%20are%20non-azure%20vms%2C%20so%20from%20my%20on-prem%20to%20azure.%20i%20can%20only%20see%20updates%20on%20the%20boxes%20since%20the%20agent%20was%20installed.%20nothing%20before%20that.%26nbsp%3B%20i%20have%20also%20tried%20to%20quarry%20to%20pull%20list%20of%20all%20the%20patches%20that%20have%20been%20applied.%20i%20have%20not%20been%20successful%20in%20that.%20i%20would%20like%20to%20at%20least%20get%20name%20of%20patches%20that%20are%20applied%20and%20maybe%20date%20with%20it.%3C%2FP%3E%3CP%3Eif%20i%20can%20get%20some%20help%20i%20would%20appreciate%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1207898%22%20slang%3D%22en-US%22%3ERe%3A%20log%20analytics%20how%20to%20pull%20all%20updates%20installed%20on%20a%20server%20with%20names%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1207898%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F573655%22%20target%3D%22_blank%22%3E%40kashifhafeez%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhat%20have%20you%20got%20so%20far%2C%20have%20you%20created%20a%20Log%20Analytics%20workspace%20and%20deployed%20agents%20to%20the%20server(s).%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20is%20an%20update%20management%20solution%20you%20can%20deploy.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fautomation-update-management%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fautomation-update-management%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3EYou%20can%20use%20the%20Update%20Management%20solution%20in%20Azure%20Automation%20to%20manage%20operating%20system%20updates%20for%20your%20Windows%20and%20Linux%20machines%20in%20Azure%2C%20in%20on-premises%20environments%2C%20and%20in%20other%20cloud%20environments.%20You%20can%20quickly%20assess%20the%20status%20of%20available%20updates%20on%20all%20agent%20machines%20and%20manage%20the%20process%20of%20installing%20required%20updates%20for%20servers.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EExample%20queries%20can%20be%20found%26nbsp%3Bhere%3A%3CEM%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fautomation-update-management-query-logs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fautomation%2Fautomation-update-management-query-logs%3C%2FA%3E%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

been trying to get a list of all the updates that are installed on a server ? just cant find anything on it. im new to this so if anyone can help

10 Replies

@kashifhafeez 

 

What have you got so far, have you created a Log Analytics workspace and deployed agents to the server(s).  

 

There is an update management solution you can deploy.

 

https://docs.microsoft.com/en-us/azure/automation/automation-update-management

You can use the Update Management solution in Azure Automation to manage operating system updates for your Windows and Linux machines in Azure, in on-premises environments, and in other cloud environments. You can quickly assess the status of available updates on all agent machines and manage the process of installing required updates for servers.

 

Example queries can be found here:https://docs.microsoft.com/en-us/azure/automation/automation-update-management-query-logs

@CliveWatson 
Then you for the response Clive. 
I have a Windows and Linux OMS agent installed. i am able to pull data from Windows OMS agent and apply updates and see what updates and patches are missing.  these are non-azure vms, so from my on-prem to azure. i can only see updates on the boxes since the agent was installed. nothing before that.  i have also tried to quarry to pull list of all the patches that have been applied. i have not been successful in that. i would like to at least get name of patches that are applied and maybe date with it.

if i can get some help i would appreciate it.

@kashifhafeez 

 

That is how the agent works, data is from installation time.  If you wanted older data you'd have to use the Log Analytocs api to import it, but that's not a trivial piece of work.

@CliveWatson thank you, sir! that helps alot coming from an MVP. i can take that let the boss know i was right the first time.

@CliveWatson 

Hi Clive, I've got Update Management setup and it works in terms of installing updates. I want a way to ascertain what patches and versions (as well as packages with versions for Linux) are installed on  a particular box. This can then be compared against an external database of patch information to ascertain if any patches have been installed outside of the approval process.

The information in Log Analytics does not appear to provide this, though I haven't worked much with Log Analytics so it's possible I don't know how. I have searched online and can't find the answer, hence commenting here.

Is there a way to query an API or something and get a JSON back, please? Or indeed go direct to the VM agent? Anything that shows that current state of the VM would be helpful, ideally with some audit information.

Thanks,

Neil.

@CliveWatsonHi Clive. Thanks for the reply. Yes I saw those and they do provide useful information but from what I can see it all pertains to what Update Management did rather than the current status of a machine. I wanted a way to ascsertain what updates/packages were on a machine regardless of how they were installed, which I don't seem to be able to find. It doesn't look like manually installed updates/packages would be logged anywhere. Or have I missed the query?!

Neil.

@neilashbysenior  I think Usage only shows the required updates, not what is there.   Others may know more as I'm not familiar with the data itself. 

@neilashbysenior Did you find a solution for this topic? I am experiencing the same issue. The idea is to check if certain KBs are installed, to ensure that some CVEs are patched...

Hi @MiguelAND, not directly, I ended up using logs from an Elastic beat on the box itself to provide the information with which we could alert if an update was installed outside of Update Management. You could probably get the same information from the Windows Event Logs going into Log Analytics.