Use CMPivot to query Windows Update event data and ConfigMgr client logs on connected devices; use a separate remote execution or collection method when you need the complete Windows Update diagnostic file. In the Configuration Manager console, open Assets and Compliance → Device Collections, select a small test collection, and choose Start CMPivot. CMPivot sends the query through the ConfigMgr fast channel and returns responses from clients that are currently reachable. Microsoft’s CMPivot documentation describes this operating model.
What CMPivot can—and cannot—collect
CMPivot is a fast remote triage tool. It can query Windows Event Log data with WinEvent() and read text from ConfigMgr client logs with CcmLog(). It does not automatically download arbitrary files or create a complete Windows Update diagnostic package for you.
| Investigation need | Best first method |
|---|---|
| Recent Windows Update activity across connected clients | WinEvent() in CMPivot |
| ConfigMgr scan, deployment, and compliance processing | CcmLog() in CMPivot |
| Complete Windows Update trace data | Run Get-WindowsUpdateLog on the client, or collect the client diagnostics package |
| Servicing-stack failure | CBS.log, DISM.log, and servicing events |
| WSUS or software-update-point behavior | Management-point, SUP, and WSUS logs |
Modern Windows records Windows Update diagnostics as ETW trace files rather than maintaining a permanently readable C:WindowsWindowsUpdate.log. Get-WindowsUpdateLog merges those traces into a readable file. Microsoft’s cmdlet documentation explains the conversion and its options.
Prerequisites and safe scope
- A healthy Configuration Manager current-branch site and client.
- CMPivot permission and access to the target device collection.
- Clients that are online and able to receive a fast-channel request. An offline device may return no row even when its event log contains relevant entries.
- A client version that supports the entity and syntax you use. CMPivot schemas can differ by release, so use IntelliSense in your console.
- A deliberately chosen time range. Start with a small collection and avoid querying weeks of verbose events across a large fleet.
- Accurate clocks and recorded time zones so client, deployment, WSUS, and server timestamps can be correlated.
Event messages can contain usernames, paths, update titles, and other operational details. Limit the collection and handle exported results according to your organization’s data policy.
Recommended Free Tools
#1 Best Overall
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
Start a CMPivot session
- In the Configuration Manager console, go to Assets and Compliance → Device Collections.
- Select the collection containing the affected clients.
- Choose Start CMPivot.
- Run an unfiltered entity query first when you are unsure of the returned column names. Then add
project,where, and sorting clauses.
CMPivot uses a subset of Kusto Query Language. Results from connected clients are near-real-time responses; other entities can expose cached data. For tenant-attached sessions, reduce result size with filters, project, take, or top, because Microsoft documents a response timeout after 10 minutes without a response. See the tenant-attach CMPivot overview.
Query Windows Update event logs
Start with the operational channel
WinEvent() queries Windows Event Log and ETW-generated events. Its default window is 24 hours; supply a timespan for older incidents. Microsoft documents the entity and timespan behavior.
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 24 h)
| order by TimeGenerated desc
For a broader incident window:
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc
Column names can vary with the ConfigMgr implementation. If Message or TimeGenerated is rejected, run the entity without a pipeline, inspect the columns returned by your console, and add fields one at a time.
Focus on warnings and errors
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| where LevelDisplayName in ('Warning', 'Error')
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc
Filter likely update-related event IDs
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| where EventID in (19, 20, 21, 31, 34, 35, 36, 43, 44)
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc
This list is a narrowing aid, not a universal Windows contract. IDs and messages vary by Windows build and update scenario. Begin with recent events, identify the IDs that matter in your environment, then filter.
Rank #2
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
Summarize affected devices
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| where LevelDisplayName in ('Warning', 'Error')
| summarize EventCount=count() by Device, EventID, LevelDisplayName
| order by EventCount desc
Check the classic System log when necessary
Current Windows systems usually provide more useful update activity in the dedicated operational channel, but some environments also expose provider events in System.
WinEvent('System', 7 d)
| where ProviderName like '%WindowsUpdate%'
or Source like '%WindowsUpdate%'
| project Device, TimeGenerated, EventID, LevelDisplayName, Message
| order by TimeGenerated desc
If this returns nothing, run WinEvent('System', 7 d) without a provider filter. Provider and column names differ across implementations, and not every Windows Update event is written to System.
Query ConfigMgr software-update logs
CcmLog() lets you search client log text remotely. Microsoft’s Configuration Manager log reference defines the roles of these logs.
Windows Update Agent interaction
CcmLog('WUAHandler', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc
WUAHandler.log records ConfigMgr’s interaction with the Windows Update Agent, including searches.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Scan, download, and installation processing
CcmLog('UpdatesHandler', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc
UpdatesHandler.log covers software-update compliance scanning, downloading, and installation.
Deployment evaluation and enforcement
CcmLog('UpdatesDeployment', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc
UpdatesDeployment.log shows assignment activation, evaluation, and enforcement.
Compliance and state reporting
CcmLog('UpdatesStore', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc
CcmLog('StateMessage', 7 d)
| project Device, LogDateTime, LogText
| order by LogDateTime desc
UpdatesStore.log records compliance processing; StateMessage.log records software-update state messages sent to the management point.
Find likely failures
CcmLog('WUAHandler', 7 d)
| where LogText contains 'error'
or LogText contains 'failed'
or LogText contains '0x'
| project Device, LogDateTime, LogText
| order by LogDateTime desc
Text matching is a lead, not a diagnosis. Matching behavior can be case- or syntax-sensitive in the CMPivot implementation, and a single line rarely explains the entire transaction. Use like for wildcard searches:
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
CcmLog('WUAHandler', 7 d)
| where LogText like '%0x%'
| project Device, LogDateTime, LogText
Correlate the client evidence
- Run the Windows Update operational-channel query and note device, timestamp, event ID, update title or KB, and any HRESULT or hexadecimal code.
- Search
WUAHandleraround that timestamp to confirm ConfigMgr’s Windows Update Agent interaction. - Review
UpdatesHandlerfor scan, download, and installation activity. - Review
UpdatesDeploymentfor assignment evaluation, deadline, maintenance-window, and enforcement behavior. - Check
UpdatesStoreandStateMessagefor compliance and reporting state. - Compare the timeline with reboot state, content availability, and the deployment deadline.
- If client evidence is inconclusive, continue at the management point, SUP, WSUS, and distribution point.
| Observed symptom | First logs to inspect |
|---|---|
| Client did not scan | WUAHandler.log and Windows Update operational events |
| Deployment was not evaluated | UpdatesDeployment.log |
| Update downloaded but did not install | UpdatesHandler.log and Windows Update events |
| Compliance is incorrect or stale | UpdatesStore.log and StateMessage.log |
| Content is unavailable | UpdatesHandler.log, CAS.log, ContentTransferManager.log, and DataTransferService.log |
| Servicing failed | CBS.log, DISM.log, and Windows servicing events |
Do not assume a Windows Update event proves ConfigMgr initiated the action. Windows Update for Business, Intune, Microsoft Update, manual scans, scheduled tasks, and other tools can produce the same Windows Update activity. Identify update-workload ownership on co-managed devices before assigning responsibility.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Generate a complete readable Windows Update log
Run this command on the affected client, not merely on the administrator’s workstation:
New-Item -ItemType Directory -Path C:Temp -Force
Get-WindowsUpdateLog -LogPath C:TempWindowsUpdate.log -ForceFlush
To include Windows Update, Update Session Orchestrator, and update user-interface traces:
Get-WindowsUpdateLog -IncludeAllLogs -LogPath C:TempWindowsUpdate-All.log -ForceFlush
-ForceFlush asks Windows Update to flush active traces before conversion; -LogPath sets the output location. Conversion can be slow, traces can roll over, and permissions are required to read the ETL source and write the destination. Microsoft documents Windows 10 version 1709 (OS build 16299) as an important boundary for symbol-server and decoding behavior.
Best Value
- 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
- Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
- 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
- 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
- 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
Retrieve the resulting file through an approved workflow: ConfigMgr Run Scripts followed by controlled collection, ConfigMgr client diagnostics, PowerShell remoting, a secured administrative share, or another endpoint-management collection process. Plan for network reachability, administrative rights, storage, retention, and sensitive log content. CMPivot itself does not turn this command into a file-transfer operation.
When CMPivot returns no useful data
No CMPivot response
- Confirm the device is in the selected collection and currently online.
- Check client notification and state-message health, including
CcmNotificationAgent.logandStateMessage.log. - On the site server, inspect
BgbServer.log; in the console, inspectCMPivot.log. - Verify the client version supports the entity.
Microsoft lists CMPivot-related server and client logs in its CMPivot documentation.
The event channel is empty
- Confirm
Microsoft-Windows-WindowsUpdateClient/Operationalexists and is enabled in Event Viewer. - Expand the window beyond 24 hours.
- Test a known device with recent update activity.
- Run the unfiltered operational query, then test
System.
A column or operator fails
Run the entity alone, inspect the schema supplied by IntelliSense, and add one projection or filter at a time. Do not assume every ConfigMgr release exposes identical display-name fields.
Results are too large
WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 2 h)
| where LevelDisplayName in ('Warning', 'Error')
| project Device, TimeGenerated, EventID, Message
| take 500
For fleet-wide counts, summarize instead of returning every message:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →WinEvent('Microsoft-Windows-WindowsUpdateClient/Operational', 7 d)
| summarize count() by Device, EventID
| order by count_ desc
Get-WindowsUpdateLog fails
- Create the destination directory and confirm write permission.
- Run the command on the affected computer.
- Flush traces and retry.
- Check that the ETL files have not rolled over and that the Windows version fits Microsoft’s documented decoding assumptions.
Alternatives for escalation
Use ConfigMgr client diagnostics when a broader package is needed; use Run Scripts or PowerShell remoting for controlled on-device conversion; and use Intune device diagnostics when the device is appropriately enrolled and managed. After collection, review ConfigMgr logs with CMTrace, OneTrace, or Support Center Log File Viewer, as described in Microsoft’s log-file viewer documentation. For command-line event export, Microsoft documents wevtutil at Windows Commands.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




