Create a Maintenance Window
You can create a maintenance window to restrict when Qualys TruRisk™ Eliminate is allowed to deploy patches to your assets, either across your entire subscription or to specific assets using tags.
Navigate to TE > Configuration > Maintenance Window. Click Create Maintenance Window.
If you plan to create a Tag Based Maintenance Window, make sure the relevant asset tags already exist before you start. If your assets have a Cloud Agent Reduced Activity Period (RAP) configured, review that schedule first, since RAP takes precedence over a Maintenance Window whenever the two overlap. For more information, see Maintenance Windows Overview.
Navigate to TE > Configuration > Maintenance Window. Click Create Maintenance Window. On the Create: Maintenance Window window, perform the following steps:
1. Basic Details
Enter a Name and, optionally, a Description for the maintenance window, then click Next.
2. Scope
Select the scope of the maintenance window:
- Global: The maintenance window applies to every patch-enabled asset in your subscription.
- Tag-based: The maintenance window applies only to assets carrying specific tags. Click
and select up to 10 tags from the tag selector. Assets matching any of the selected tags are included.
Click Next.
Important to Know
- If both Global and Tag-Based maintenance windows are enabled for an asset, only the tag-based maintenance window is applied.
- You need at least one tag selected to save a Tag-based Maintenance Window.
- You cannot change the scope type (Global or Tag-based) after the maintenance window is created. You can still add or remove tags on a Tag-based window later, provided at least one tag remains.
3. Schedule
Choose whether the Maintenance Window runs once or repeats:
i) Run Once — the window occurs a single time. Choose:
- Single-day window: Runs once, on one date, between a start time and end time you set.
- Multi-day window: Runs once, continuously, across a date range. Set the Start Date, Start Time, End Date, and End Time.
ii) Recurring: The window repeats automatically. Select how it repeats:
- Daily: The same start time and end time apply every day.
- Weekly: Select Single-day window (select one or more days of the week; the same start time and end time repeat on each selected day every week) or Multi-day window (pick a start day/time and an end day/time within the week; the window stays open continuously across those days every week).
- Monthly: Available as a single occurrence only. Define the day using one of three options: a specific calendar date each month, a specific weekday occurrence each month (for example, the third Sunday), or Patch Tuesday, offset by up to 27 days before or after.
For either option, set the Start Time and End Time, then select a Time Zone, the Agent Time Zone (the asset's local time zone), or a specific UTC offset. The page displays a plain-language summary of the schedule you have configured. Use it to confirm that the window behaves as you expect.
If the maintenance window's schedule overlaps with a configured Reduced Activity Period (RAP), the RAP takes precedence.
Click Next.
4. Review & Confirm
Review the Name, Description, Scope, and Schedule summary, then click Save.
The Maintenance Window is created and is displayed in the Maintenance Window list. Its status is Enabled by default.
Important to Know
- To run a job's patching activity only within this Maintenance Window, the deployment job targeting these assets must be scheduled to overlap with the window, or configured to defer to the next available window.
- From the Maintenance Window list, use the Quick Actions menu to Edit, Enable/Disable, or Delete a Maintenance Window at any time.
For example, if a deployment job is scheduled to run at 2:00 PM but its target assets have a Maintenance Window active only from 5:00 PM to 10:00 PM, the job does not run at 2:00 PM. If the job is set to Defer to Next Maintenance Window, it runs automatically at 5:00 PM instead; otherwise, it fails with a status indicating that no active Maintenance Window was found.
The maintenance window related job and asset statuses (such as Deferred, Timed Out, or Failed due to Maintenance Window) can be viewed on the Job Status and Asset Vulnerability tabs of the deployment job.
Related Topics