[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

how to wmi filtering query

Posted on 2012-03-12
10
Medium Priority
?
879 Views
Last Modified: 2012-03-16
hi after been told about 'wmi filtering' i have attempted a practical test as below:

currently i have 3 separate types of 'ou's/gpo ie:

- domain controller - x 1
- member servers - win 2003 - wsus/isa 2006/wds
- host pc - xp type

i have also configured my gpo's via computer configuration using 'admin account for all above machines just to receive updates from 'wsus' & all machines working successfully!!!

wmi filter - added:

ive followed the step by step instructions from 'option 2' and currently running the: gpupdate on all my windows 2003 os.

option 1.  basic explanation: http://support.microsoft.com/kb/555253

option 2.  a more clear explanation showing 5 steps:  http://community.spiceworks.com/how_to/show/1432

I understand what i have done but in my mind other than linking via each gpo i have to the 'wmi filters x 3 i had created it has not done anything from a visual/practical point of view!!!

detects - win 2003 machines that are not domain controllers:
- select * from Win32_OperatingSystem where Version like "5.2%" and ProductType="3"

detects - win 2003 machines that are domain controllers:
- select * from Win32_OperatingSystem where Version like "5.2%" and ProductType="2

detects - xp machines:
- select * from Win32_OperatingSystem where Version like "5.1%"

question 1.  can anyone advise me ?

would be appreciated!!!
0
Comment
Question by:mikey250
  • 6
  • 4
10 Comments
 
LVL 26

Accepted Solution

by:
Leon Fester earned 2000 total points
ID: 37709745
WMI filtering gives you the power to specify GPO's based on a certain criteria.
In your case it may not have been a practical application.

If you've got the same policy for all machines then it doesn't make a difference enabling WMI filtering.

It is specifically when you need to apply the same policy but with difference settings.

e.g. in your case; 3 OU's with different WSUS settings
domain controller - download updates and prompt me to install.
- member servers - download updates and install, no automatic reboots
- host pc - automatically download updates and install and reboot

You can add all machines to the same OU, with WMI filtering each will get their own settings.
0
 

Author Comment

by:mikey250
ID: 37709777
hi the 3 'ous/gpo's' in place were just to get the updates via 'wsus member server' as we already know!:)

so if i was to do the following:

- group of users - set with redirection folder pointing to on destination server
- a single user - set with redirection folder pointing to another destination server or mapped driver

question 1.  so doing something like the above is how 'wmi filters' are used ?

question 2.  if i did set something in the gpo that maybe was incorrect and then when i run a 'wmi filter' then the 'filter' would not work, but how would i know ?
0
 
LVL 26

Assisted Solution

by:Leon Fester
Leon Fester earned 2000 total points
ID: 37709846
Q1. Yes, you're getting the feel of WMI filtering.
WMI filtering is only applied when the condition is met, so always make sure that your queries return TRUE or else the policy won't be applied.

Q2. Broken policies would have to be checked per machine. You can run gpresult /v on a machine to test what policies are applied and the settings for each policy.
Alternatively run rsop.msc to see the settings and GPO's applied in a console view.

You can drill down to the setting and check if it is being applied.

You could also check the Event log, you should see when GPO's are being applied.
It won't tell you which GPO's were applied though.
For that you'll use the two tools mentioned above.
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 26

Assisted Solution

by:Leon Fester
Leon Fester earned 2000 total points
ID: 37709857
Almost forgot, you can use the Group Policy Modeling Wizard to test GPO's before doing any live testing.

http://www.petri.co.il/group-policy-object-modeling-windows-server-2008.htm
0
 

Author Comment

by:mikey250
ID: 37709913
yes understood but i thought 'wmi filtering' was what was used to test a gpo before configuration took place as it would apparantely 'not' activate, which is especially useful if on wrong version of machine on a global scale anyway or not just a small scale !!! ?


i will look at the 'gpo wizard'

thanks!!!
0
 

Author Comment

by:mikey250
ID: 37710195
hi dvt_localboy,

yes i have run: gpresult /v - ok

im now beginning to understand the difference between the both:

wmi filter:

currently i add some filter commands to only detect the following:

- window 2003 non domain controllers
- windows 2003 domain controllers
- xp machine

win 2003 - resultant set of policy or win 2008  gp modelling wizard (none as):

i followed the instructions as per:

- http://www.petri.co.il/group-policy-object-modeling-windows-server-2008.htm

and although i did not have to link to my 'wmi filters' i did do, which also stated while following the 'wizard' that my filters were 'true'.!!!!!!!! ok

at the end of the 'wizard' detecting specifically my domain controller it prompted another window in 'gpmc' showing me a summary of my domain controllers settings that i had set in gpo aswell as defaults it appears. - ok

ok getting there!!

wmi filters:

- so i could have 2 host xp machines with 2 different types of software so using the filter enables me to distinguish between the both.
- if these types of distinctions were not really needed then 'wmi filter' would not be used. (purely preferential)!!!!

resultant set of policy: - this detects if a gpo was functional so i could then troubleshoot!!

- taking into consideration the 2 'wmi filters' i have added, i may want to setup a gpo specific to each of those specific 2 host xp machines, so directing the wizard through the filters ensures the specific host xp is configured correctly!!

additionally doing checks also with:

- gpudpate
- gpupdate /force
- gpresult /v
- rsop
- eventviewer
0
 

Author Comment

by:mikey250
ID: 37710472
after configuring the 'wmi filter & rsop' on windows 2003, i also ran a backup of gpo as per this 'url':

http://www.petri.co.il/backing-up-group-policy-objects.htm

- i created a folder on a spare partitioned drive on my domain controller and shared specifically for 'administrator account'.

- i then opened selected to 'view' my specific gpo settings, which allows me to narrow down and troubleshoot a specific issue with maybe one of my gpo settings. - ok
0
 

Author Closing Comment

by:mikey250
ID: 37728699
sound advice!
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37728753
Hey man, sorry I didn't see any of your other posts. Hence the lack of  response. Glad you got it sort and thanks.
0
 

Author Comment

by:mikey250
ID: 37728801
no probs thanks!! apreciated!
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Common practice undertaken by most system administrators is to document the configurations and final solutions of anything performed by them for their future use and reference. So here I am going to explain how to export ISA Server 2004 Firewall pol…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question