Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
CMPivot

How to Collect Windows Update Logs Remotely from an SCCM/ConfigMgr Client with CMPivot

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use CMPivot to query Windows Update event data and ConfigMgr client logs on connected devices; use a separate remote execution or collection method when you need the complete Windows Update diagnostic file. In the Configuration Manager console, open Assets and Compliance → Device Collections, select a small test collection, and choose Start CMPivot. CMPivot sends the query through the ConfigMgr fast channel and returns responses from clients that are currently reachable. Microsoft’s CMPivot documentation describes this operating model.

What CMPivot can—and cannot—collect

CMPivot is a fast remote triage tool. It can query Windows Event Log data with WinEvent() and read text from ConfigMgr client logs with CcmLog(). It does not automatically download arbitrary files or create a complete Windows Update diagnostic package for you.

Investigation need Best first method
Recent Windows Update activity across connected clients WinEvent() in CMPivot
ConfigMgr scan, deployment, and compliance processing CcmLog() in CMPivot
Complete Windows Update trace data Run Get-WindowsUpdateLog on the client, or collect the client diagnostics package
Servicing-stack failure CBS.log, DISM.log, and servicing events
WSUS or software-update-point behavior Management-point, SUP, and WSUS logs

Modern Windows records Windows Update diagnostics as ETW trace files rather than maintaining a permanently readable C:WindowsWindowsUpdate.log. Get-WindowsUpdateLog merges those traces into a readable file. Microsoft’s cmdlet documentation explains the conversion and its options.

Prerequisites and safe scope

  • A healthy Configuration Manager current-branch site and client.
  • CMPivot permission and access to the target device collection.
  • Clients that are online and able to receive a fast-channel request. An offline device may return no row even when its event log contains relevant entries.
  • A client version that supports the entity and syntax you use. CMPivot schemas can differ by release, so use IntelliSense in your console.
  • A deliberately chosen time range. Start with a small collection and avoid querying weeks of verbose events across a large fleet.
  • Accurate clocks and recorded time zones so client, deployment, WSUS, and server timestamps can be correlated.

Event messages can contain usernames, paths, update titles, and other operational details. Limit the collection and handle exported results according to your organization’s data policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start a CMPivot session

  1. In the Configuration Manager console, go to Assets and Compliance → Device Collections.
  2. Select the collection containing the affected clients.
  3. Choose Start CMPivot.
  4. Run an unfiltered entity query first when you are unsure of the returned column names. Then add project, where, and sorting clauses.

CMPivot uses a subset of Kusto Query Language. Results from connected clients are near-real-time responses; other entities can expose cached data. For tenant-attached sessions, reduce result size with filters, project, take, or top, because Microsoft documents a response timeout after 10 minutes without a response. See the tenant-attach CMPivot overview.

Query Windows Update event logs

Start with the operational channel

WinEvent() queries Windows Event Log and ETW-generated events. Its default window is 24 hours; supply a timespan for older incidents. Microsoft documents the entity and timespan behavior.

WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 24 h)
| order by TimeGenerated desc

For a broader incident window:

WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc

Column names can vary with the ConfigMgr implementation. If Message or TimeGenerated is rejected, run the entity without a pipeline, inspect the columns returned by your console, and add fields one at a time.

Focus on warnings and errors

WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| where LevelDisplayName in ('Warning', 'Error')
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc

Filter likely update-related event IDs

WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| where EventID in (19, 20, 21, 31, 34, 35, 36, 43, 44)
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc

This list is a narrowing aid, not a universal Windows contract. IDs and messages vary by Windows build and update scenario. Begin with recent events, identify the IDs that matter in your environment, then filter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Summarize affected devices

WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| where LevelDisplayName in ('Warning', 'Error')
| summarize EventCount=count() by Device, EventID, LevelDisplayName
| order by EventCount desc

Check the classic System log when necessary

Current Windows systems usually provide more useful update activity in the dedicated operational channel, but some environments also expose provider events in System.

WinEvent('System', 7 d)
| where ProviderName like '%WindowsUpdate%'
   or Source like '%WindowsUpdate%'
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc

If this returns nothing, run WinEvent('System', 7 d) without a provider filter. Provider and column names differ across implementations, and not every Windows Update event is written to System.

Query ConfigMgr software-update logs

CcmLog() lets you search client log text remotely. Microsoft’s Configuration Manager log reference defines the roles of these logs.

Windows Update Agent interaction

CcmLog('WUAHandler', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc

WUAHandler.log records ConfigMgr’s interaction with the Windows Update Agent, including searches.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3

Scan, download, and installation processing

CcmLog('UpdatesHandler', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc

UpdatesHandler.log covers software-update compliance scanning, downloading, and installation.

Deployment evaluation and enforcement

CcmLog('UpdatesDeployment', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc

UpdatesDeployment.log shows assignment activation, evaluation, and enforcement.

Compliance and state reporting

CcmLog('UpdatesStore', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc
CcmLog('StateMessage', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc

UpdatesStore.log records compliance processing; StateMessage.log records software-update state messages sent to the management point.

Find likely failures

CcmLog('WUAHandler', 7 d)
| where LogText contains 'error'
    or LogText contains 'failed'
    or LogText contains '0x'
| project Device, LogDateTime, LogText
| order by LogDateTime desc

Text matching is a lead, not a diagnosis. Matching behavior can be case- or syntax-sensitive in the CMPivot implementation, and a single line rarely explains the entire transaction. Use like for wildcard searches:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
CcmLog('WUAHandler', 7 d)
| where LogText like '%0x%'
| project Device, LogDateTime, LogText

Correlate the client evidence

  1. Run the Windows Update operational-channel query and note device, timestamp, event ID, update title or KB, and any HRESULT or hexadecimal code.
  2. Search WUAHandler around that timestamp to confirm ConfigMgr’s Windows Update Agent interaction.
  3. Review UpdatesHandler for scan, download, and installation activity.
  4. Review UpdatesDeployment for assignment evaluation, deadline, maintenance-window, and enforcement behavior.
  5. Check UpdatesStore and StateMessage for compliance and reporting state.
  6. Compare the timeline with reboot state, content availability, and the deployment deadline.
  7. If client evidence is inconclusive, continue at the management point, SUP, WSUS, and distribution point.
Observed symptom First logs to inspect
Client did not scan WUAHandler.log and Windows Update operational events
Deployment was not evaluated UpdatesDeployment.log
Update downloaded but did not install UpdatesHandler.log and Windows Update events
Compliance is incorrect or stale UpdatesStore.log and StateMessage.log
Content is unavailable UpdatesHandler.log, CAS.log, ContentTransferManager.log, and DataTransferService.log
Servicing failed CBS.log, DISM.log, and Windows servicing events

Do not assume a Windows Update event proves ConfigMgr initiated the action. Windows Update for Business, Intune, Microsoft Update, manual scans, scheduled tasks, and other tools can produce the same Windows Update activity. Identify update-workload ownership on co-managed devices before assigning responsibility.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Generate a complete readable Windows Update log

Run this command on the affected client, not merely on the administrator’s workstation:

New-Item -ItemType Directory -Path C:Temp -Force
Get-WindowsUpdateLog -LogPath C:TempWindowsUpdate.log -ForceFlush

To include Windows Update, Update Session Orchestrator, and update user-interface traces:

Get-WindowsUpdateLog -IncludeAllLogs -LogPath C:TempWindowsUpdate-All.log -ForceFlush

-ForceFlush asks Windows Update to flush active traces before conversion; -LogPath sets the output location. Conversion can be slow, traces can roll over, and permissions are required to read the ETL source and write the destination. Microsoft documents Windows 10 version 1709 (OS build 16299) as an important boundary for symbol-server and decoding behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

Retrieve the resulting file through an approved workflow: ConfigMgr Run Scripts followed by controlled collection, ConfigMgr client diagnostics, PowerShell remoting, a secured administrative share, or another endpoint-management collection process. Plan for network reachability, administrative rights, storage, retention, and sensitive log content. CMPivot itself does not turn this command into a file-transfer operation.

When CMPivot returns no useful data

No CMPivot response

  • Confirm the device is in the selected collection and currently online.
  • Check client notification and state-message health, including CcmNotificationAgent.log and StateMessage.log.
  • On the site server, inspect BgbServer.log; in the console, inspect CMPivot.log.
  • Verify the client version supports the entity.

Microsoft lists CMPivot-related server and client logs in its CMPivot documentation.

The event channel is empty

  • Confirm Microsoft-Windows-WindowsUpdateClient/Operational exists and is enabled in Event Viewer.
  • Expand the window beyond 24 hours.
  • Test a known device with recent update activity.
  • Run the unfiltered operational query, then test System.

A column or operator fails

Run the entity alone, inspect the schema supplied by IntelliSense, and add one projection or filter at a time. Do not assume every ConfigMgr release exposes identical display-name fields.

Results are too large

WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 2 h)
| where LevelDisplayName in ('Warning', 'Error')
| project Device, TimeGenerated, EventID, Message
| take 500

For fleet-wide counts, summarize instead of returning every message:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| summarize count() by Device, EventID
| order by count_ desc

Get-WindowsUpdateLog fails

  • Create the destination directory and confirm write permission.
  • Run the command on the affected computer.
  • Flush traces and retry.
  • Check that the ETL files have not rolled over and that the Windows version fits Microsoft’s documented decoding assumptions.

Alternatives for escalation

Use ConfigMgr client diagnostics when a broader package is needed; use Run Scripts or PowerShell remoting for controlled on-device conversion; and use Intune device diagnostics when the device is appropriately enrolled and managed. After collection, review ConfigMgr logs with CMTrace, OneTrace, or Support Center Log File Viewer, as described in Microsoft’s log-file viewer documentation. For command-line event export, Microsoft documents wevtutil at Windows Commands.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$304.99
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.