A.In the left panel of Event Viewer, click Application and Service Logs. B.Expand Microsoft, and then expand Windows. C.Click WindowsUpdateClient, and then click Operational. D.Check to see if Event ID 40 is present in the event list. Reference Links: Event ID 25 from Microsoft-Windows-WindowsUpdateClient. Sep 18, 2018 A Revision ID (do no confuse this with “revision number”) is a serial number that's issued when an update is initially published or revised on a given service. An existing update that’s revised keeps the same update ID (GUID), has its revision number incremented (for example, from 100 to 101), but gets a completely new revision ID that is not related to the previous ID. Press the Win + X keys or right-click the Start button and select Event Viewer in the context menu. In Event Viewer, go to Applications and Service Logs Microsoft Windows WindowsUpdateClient Operational. Select the events in the middle column of the app's window to read the log in the details pane below. 1074 Logged when an app (ex: Windows Update) causes the system to restart, or when a user initiates a restart or shutdown. 6006 Logged as a clean shutdown. It gives the message 'The Event log service was stopped'. 6008 Logged as a dirty shutdown. It gives the message 'The previous system shutdown at.
Applies to: Windows 10
The following table describes the log files created by Windows Update.
![]() ![]()
Generating WindowsUpdate.log
To merge and convert WU trace files (.etl files) into a single readable WindowsUpdate.log file, see Get-WindowsUpdateLog.
Note
When you run the Get-WindowsUpdateLog cmdlet, an copy of WindowsUpdate.log file is created as a static log file. It does not update as the old WindowsUpate.log unless you run Get-WindowsUpdateLog again.
Windows Update log components
The WU engine has different component names. The following are some of the most common components that appear in the WindowsUpdate.log file:
Note
Many component log messages are invaluable if you are looking for problems in that specific area. However, they can be useless if you don't filter to exclude irrelevant components so that you can focus on what’s important.
Windows Update log structure
The Windows update log structure is separated into four main identities:
The WindowsUpdate.log structure is discussed in the following sections.
Time stamps
The time stamp indicates the time at which the logging occurs.
Process ID and thread ID
The Process IDs and Thread IDs are random, and they can vary from log to log and even from service session to service session within the same log.
Windows Update Event Id 31Component name
Search for and identify the components that are associated with the IDs. Different parts of the WU engine have different component names. Some of them are as follows:
Windows Update Client Event Id 20Update identifiersUpdate ID and revision numberEvent Id 51
There are different identifiers for the same update in different contexts. It’s important to know the identifier schemes.
Windows Update Failure Event Id 1001Revision ID
Local ID
Inconsistent terminology
Windows Setup log files analysis using SetupDiag tool
SetupDiag is a diagnostic tool that can be used for analysis of logs related to installation of Windows Updates. For detailed information, see SetupDiag.
Comments are closed.
|
AuthorWrite something about yourself. No need to be fancy, just an overview. Archives
December 2020
Categories |