Predefined Reports
Pre-defined reports provide an overarching knowledge of your network's patch and vulnerability management process. This report can be generated based on multiple parameters, which includes: patch reports, system reports, Self Service Portal (SSP) reports, and Automate Patch Deployment (APD) reports. These reports can be accessed directly through the web console. To access pre-defined reports, navigate to Threats & Patches → Reports → Predefined Reports. If the Vulnerability Management add-on is not licensed, the module is named Patch Management.
Patch Reports
Use Detailed View when the report must identify the computer associated with each patch. Apply the required Custom Group filter, then use the column chooser near the search option to enable Computer Name before exporting the results.
To combine results from multiple deployment tasks or custom groups, add a separate Deployed Using or Custom Group criterion for each required value, apply the filter, and export the consolidated Detailed View. The Deployed Using column identifies whether a patch was deployed through an APD task, Manual Deployment, or another deployment task.
To compare an earlier patch with its replacement, review the Installed Patch Report and Missing Patch Report separately. The Installed Date field is available only for patches deployed through Endpoint Central MSP; these reports do not combine both patches and installation dates in one view.
Reports contain data only for computers that are currently managed. Computers deleted from the console are not included because their data is no longer retained.
The Patch Reports provides you with detailed information about the vulnerable systems in your network and the patch details to fix the vulnerability. It provides data on the following:
Create a filtered security patch report
To report security patches installed for a custom group, navigate to Threats & Patches → Patches → Detailed View, create a filter, apply it, and export the results.
- Select a Custom Group. Dynamic groups are not supported for this filter.
- Set Patch Status to Installed.
- Set Patch Type to Security and select the required Operating System (Patch).
- Set Deployed Date to the required date range when you need patches deployed through Endpoint Central MSP.
The Deployed Date filter includes only patches deployed through Endpoint Central MSP. An empty Deployed Time column means the patch was not deployed through Endpoint Central MSP, so those machines are dropped when Deployed Date is applied. For a wider report, use Release Date instead of Deployed Date.
- Applicable Patches Report: This report displays the list of patches that are ready to be deployed to your managed network. This report includes patches that are previously deployed as well. It provides you with the details of the patches that are applicable to your network and the affected systems. By default, it lists the details of the patches released in the current month. You have an option to select a different period or to specify a custom period and generate the report. The detailed information of reports is as follows:
- Patch ID: A unique reference ID in Endpoint Central MSP for every patch.
- Bulletin ID: The advisory article provided by the vendor, which contains information about the vulnerability and patch availability. Clicking this option will lead you to the Bulletin Details view, which provides more info about the Bulletin and the vulnerability.
- Patch Name: The name of the patch. Clicking this option will lead you to the Patch Details view, which provides more details about the patch.
- Severity: Determines the importance of the patch. These severity ratings are as per the bulletin or advisory information.
- Affected Systems: Refers to the total count of the systems that require this patch to be installed. This also includes the systems where the patch has already been installed.
- Installed Systems: Refers to the count of the systems where the patch has been installed.
- Missing Systems: Refers to the count of the systems that do not have the patches installed yet.

- Supported Patches Report: The Supported Patches Report provides the details of all the patches supported by Endpoint Central MSP released by the vendor websites irrespective of whether these patches have a relation to your network or not. The Supported Patches Report will be of absolute use when you plan to upgrade the systems in your network by installing the latest applications/ updates available for the application.

- Missing Patches Awaiting Approval: The Missing Patches Report will list down all missing patches and requires approval for deployment.

- Remote Office Patch Summary: The Remote Office Patch Summary gives an overview of the managed computers, highly vulnerable/vulnerable/healthy systems, applicable/missing/installed patches in the remote offices of the enterprise.

- Patch Compliance Report: This report displays a comprehensive patch-level deployment summary along with its compliance status. The compliance settings can be configured to adjust the percentage to mark a patch as compliant.

System Reports
The System Reports provides you a complete summary about the managed systems in the enterprise. The following reports can be generated under the System Reports:
- System Health Report: This report displays the health status and the number of missing OS and third-party patches in each system.
To filter Highly Vulnerable Systems by computer, open Systems → Health Summary → Highly Vulnerable Systems. Do not put quotation marks around the Computer Name value. For a few computers, add one Computer Name / like filter row per name and join the rows with OR, not AND. For many computers, create a Static Custom Group and, in the same view, set the filter to Custom Group / equal / the group name. Use that filter on the report or view; do not open the Custom Groups page to review missing patches.

- System requiring reboot: This report will list down all the systems in which reboot is required for installing the patches deployed.

- System Compliance Report: This report lists the compliance status of all systems in the enterprise. In Configure Compliance Settings, set Mark systems as compliant if they achieve a patch compliance of to the required percentage and Mark systems as non-compliant if they have not been scanned in the last to the required number of Day(s). Both settings apply. A computer scanned within the configured day window can still be Non-compliant if its patch compliance is below the required percentage. Setting patch compliance to 100% means the applicable patch count must equal the installed patch count; therefore, all missing patches must be installed. To generate the report for patches released within a date range, open System Compliance Report, create a filter, set Release Date to the required range, apply the filter, and export the report.

- Remote Office Compliance Graph: This report will list down the compliant status of all the systems in the remote offices managed by the enterprise.

Automate Patch Deployment (APD) Reports
- Systems with APD tasks: This report provides information on all the managed systems which have active Automatic Patch Deployment (APD) tasks.

- Systems without APD tasks: This report provides information on all the managed systems which do not have any Automatic Patch Deployment (APD) tasks.

Self-Service Portal (SSP) Reports
- Patches yet to be installed: This report will list down all the patches available in the Self-Service Portal and is awaiting installation.

- Patch Deployment list: This report will list the configuration through which patches are published to the Self-Service Portal.

- Detailed View: This report lists all the details of the patches which are published to the Self-Service Portal.
