Maintenance Windows

A Maintenance Window defines a period during which system maintenance occurs on a device. Business Unit configurations include Maintenance Window settings so administrators can schedule maintenance activities. Tenable Patch Management installs patches only during the defined Maintenance Window.

Maintenance Windows can include one or more schedules that deploy based on urgency settings (Low, Normal, High, and Critical). Urgency settings are cumulative, so higher urgencies inherit any settings specified at lower urgencies.

Overlapping time settings do not have a restrictive effect, but Tenable Patch Management recommends keeping your Maintenance Window time settings simple. When a patch encounters multiple time settings for Maintenance Windows, it reviews one after another until it finds a match.

Tenable Patch Management provides built-in Start Time objects, available from the following path:

Schedules\Patching Schedules\Window Start

Open and Save a Maintenance Window Template

  1. Select Maintenance Windows in the left navigation menu of the Patch Dashboard.

    Note: When choosing a Maintenance Window template, be sure to consider whether patch installation requires a restart. A narrow Maintenance Window can cause the restart to occur after the Maintenance Window ends.

  2. Select Show All to display the available Maintenance Window settings. If Show All is grayed out, the table includes all available settings.

  3. Select the Name of an existing template to open it, and then save the template with a new name:

Dynamic Settings

A Dynamic Detection workflow sets the patching Maintenance Window based on the selected workflow rather than a set schedule. For more information, enter a support ticket and request help from Tenable Patch ManagementCustomer Support .

Add Dynamic Detection Workflow (Optional)

  1. Scroll down to Dynamic Settings, in an open Maintenance Window template.

  2. Select Browse to the right of Add Workflow. This opens the Add Workflow dialog.

  3. Select a workflow from the table, and then click Add Workflow in the lower-left corner.

Maintenance Windows by Urgency

Create Maintenance Windows for use with different urgency settings (Low, normal, High, or Critical) or create a single Maintenance Window that applies to all Urgencies. Because urgency settings are cumulative, any settings specified at lower urgencies are inherited by higher urgency Maintenance Windows.

The urgency configuration settings use the same template whether creating a single maintenance window for all urgencies or creating individual maintenance windows for specific urgency levels.

Apply a Maintenance Window to All Urgencies

Use the Maintenance Windows by Urgency workspace of an open Maintenance Window template to create an All Urgencies Maintenance Window. You may create multiple All Urgencies Maintenance Windows with different start times.

  1. Select the toggle for Apply to All Urgencies to enable the All Urgencies options.

    UUID-2788e068-03b7-5ebf-d73a-04c1e9180b25.png
  2. Configure the Maintenance Window schedule for patches of all urgencies:

    1. Select + Create Maintenance Window to begin.

    2. Select Browse to open the list of all available start time schedules.

    3. Select the schedule you want to add, and then select OK to close the list of schedules.

    4. Enter the number of Hours, Minutes, or Seconds after the start time setting that the Maintenance Window remains open (required), and then select Create Maintenance Window on the bottom left corner to close the dialog.

    5. Repeat Step 2 to schedule additional Maintenance Windows for all urgencies.

      UUID-95023da2-bf74-db0d-6d7c-f7e5e74831f1.png
  3. Set an All Urgencies Override Duration.

    These settings override any non-zero duration values set inn the Maintenance Window when the Maintenance Window fails to open for urgency level updates.

  4. Enter the number of Hours, Minutes, or Seconds to wait after the Maintenance Window fails to open to override the Maintenance Window duration settings.

Save and Deploy the Maintenance Window

Deploy a Maintenance Window to make it available for use in a template. If you update a Maintenance Window template that was previously deployed, you must save and deploy it again for the changes to take effect.

  1. Complete the Maintenance Window configuration (refer to Open and Save a Maintenance Window Template).

  2. Save your changes:

    Select Save & Deploy to save and deploy your configuration:

    • Select Save & Deploy to save and deploy your changes.

    • Select Save to save your changes without deploying. Be sure to return and Deploy the changes to make them available for use.

    UUID-58cc80e0-f41e-fbcc-7721-3072af77c51d.png