# Predefined Reports Pre-defined reports provide an overarching knowledge of your network's patch and vulnerability management process. This report can be generated based on multiple parameters, which includes: patch reports, system reports, Self Service Portal (SSP) reports, and Automate Patch Deployment (APD) reports. These reports can be accessed directly through the web console. To access pre-defined reports, navigate to **Threats & Patches → Reports → Predefined Reports**. If the Vulnerability Management add-on is not licensed, the module is named **Patch Management**. ## Patch Reports Use **Detailed View** when the report must identify the computer associated with each patch. Apply the required **Custom Group** filter, then use the column chooser near the search option to enable **Computer Name** before exporting the results. To combine results from multiple deployment tasks or custom groups, add a separate **Deployed Using** or **Custom Group** criterion for each required value, apply the filter, and export the consolidated Detailed View. The **Deployed Using** column identifies whether a patch was deployed through an APD task, Manual Deployment, or another deployment task. To compare an earlier patch with its replacement, review the **Installed Patch Report** and **Missing Patch Report** separately. The **Installed Date** field is available only for patches deployed through Endpoint Central MSP; these reports do not combine both patches and installation dates in one view. Reports contain data only for computers that are currently managed. Computers deleted from the console are not included because their data is no longer retained. The Patch Reports provides you with detailed information about the vulnerable systems in your network and the patch details to fix the vulnerability. It provides data on the following: ### Create a filtered security patch report To report security patches installed for a custom group, navigate to **Threats & Patches → Patches → Detailed View**, create a filter, apply it, and export the results. 1. Select a **Custom Group**. Dynamic groups are not supported for this filter. 2. Set **Patch Status** to **Installed**. 3. Set **Patch Type** to **Security** and select the required **Operating System (Patch)**. 4. Set **Deployed Date** to the required date range when you need patches deployed through Endpoint Central MSP. The **Deployed Date** filter includes only patches deployed through Endpoint Central MSP. An empty **Deployed Time** column means the patch was not deployed through Endpoint Central MSP, so those machines are dropped when **Deployed Date** is applied. For a wider report, use **Release Date** instead of **Deployed Date**. - **Applicable Patches Report**: This report displays the list of patches that are ready to be deployed to your managed network. This report includes patches that are previously deployed as well. It provides you with the details of the patches that are applicable to your network and the affected systems. By default, it lists the details of the patches released in the current month. You have an option to select a different period or to specify a custom period and generate the report. The detailed information of reports is as follows: - **Patch ID**: A unique reference ID in Endpoint Central MSP for every patch. - **Bulletin ID**: The advisory article provided by the vendor, which contains information about the vulnerability and patch availability. Clicking this option will lead you to the Bulletin Details view, which provides more info about the Bulletin and the vulnerability. - **Patch Name**: The name of the patch. Clicking this option will lead you to the Patch Details view, which provides more details about the patch. - **Severity**: Determines the importance of the patch. These severity ratings are as per the bulletin or advisory information. - **Affected Systems**: Refers to the total count of the systems that require this patch to be installed. This also includes the systems where the patch has already been installed. - **Installed Systems**: Refers to the count of the systems where the patch has been installed. - **Missing Systems**: Refers to the count of the systems that do not have the patches installed yet. ![Applicable Patch Report](https://www.manageengine.com/products/desktop-central/help/images/applicable-patch-report.png) - **Supported Patches Report**: The Supported Patches Report provides the details of all the patches supported by Endpoint Central MSP released by the vendor websites irrespective of whether these patches have a relation to your network or not. The Supported Patches Report will be of absolute use when you plan to upgrade the systems in your network by installing the latest applications/updates available for the application. ![Supported Patches Report](https://www.manageengine.com/products/desktop-central/help/images/supported-patches-report.png) - **Missing Patches Awaiting Approval**: The Missing Patches Report will list down all missing patches and requires approval for deployment. ![Missing Patch Awaiting Approval Report](https://www.manageengine.com/products/desktop-central/help/images/missing-patch-awaiting-approval-report.png) - **Remote Office Patch Summary**: The Remote Office Patch Summary gives an overview of the managed computers, highly vulnerable/vulnerable/healthy systems, applicable/missing/installed patches in the remote offices of the enterprise. ![Remote Office Patch Summary](https://www.manageengine.com/products/desktop-central/help/images/remote-office-patch-summary.png) - **Patch Compliance Report**: This report displays a comprehensive patch-level deployment summary along with its compliance status. The compliance settings can be configured to adjust the percentage to mark a patch as compliant. ![Patch Compliance Report](https://www.manageengine.com/products/desktop-central/help/images/patch-compliance-report.png) ## System Reports The System Reports provides you a complete summary about the managed systems in the enterprise. The following reports can be generated under the System Reports: - **System Health Report**: This report displays the health status and the number of missing OS and third-party patches in each system. To filter **Highly Vulnerable Systems** by computer, open **Systems → Health Summary → Highly Vulnerable Systems**. Do not put quotation marks around the Computer Name value. For a few computers, add one **Computer Name** / **like** filter row per name and join the rows with **OR**, not **AND**. For many computers, create a Static Custom Group and, in the same view, set the filter to **Custom Group** / **equal** / the group name. Use that filter on the report or view; do not open the Custom Groups page to review missing patches. ![System Health Report](https://www.manageengine.com/products/desktop-central/help/images/system-health-report.png) - **System requiring reboot**: This report will list down all the systems in which reboot is required for installing the patches deployed. ![Systems Requiring Reboot](https://www.manageengine.com/products/desktop-central/help/images/systems-requiring-reboot.png) - **System Compliance Report**: This report lists the compliance status of all systems in the enterprise. In **Configure Compliance Settings**, set **Mark systems as compliant if they achieve a patch compliance of** to the required percentage and **Mark systems as non-compliant if they have not been scanned in the last** to the required number of **Day(s)**. Both settings apply. A computer scanned within the configured day window can still be **Non-compliant** if its patch compliance is below the required percentage. Setting patch compliance to **100%** means the applicable patch count must equal the installed patch count; therefore, all missing patches must be installed. To generate the report for patches released within a date range, open **System Compliance Report**, create a filter, set **Release Date** to the required range, apply the filter, and export the report. ![System Compliance Report](https://www.manageengine.com/products/desktop-central/help/images/system-compliance-report.png) - **Remote Office Compliance Graph**: This report will list down the compliant status of all the systems in the remote offices managed by the enterprise. ![Remote Office Compliance Report](https://www.manageengine.com/products/desktop-central/help/images/remote-office-compliance-report.png) ## Automate Patch Deployment (APD) Reports - **Systems with APD tasks**: This report provides information on all the managed systems which have active Automatic Patch Deployment (APD) tasks. ![Systems with APD Tasks](https://www.manageengine.com/products/desktop-central/help/images/systems-with-apd-tasks.png) - **Systems without APD tasks**: This report provides information on all the managed systems which do not have any Automatic Patch Deployment (APD) tasks. ![Systems without APD Tasks](https://www.manageengine.com/products/desktop-central/help/images/systems-without-apd-tasks.png) ## Self-Service Portal (SSP) Reports - **Patches yet to be installed**: This report will list down all the patches available in the Self-Service Portal and is awaiting installation. ![Self-Service Portal patch report](https://www.manageengine.com/products/desktop-central/help/images/ssp-report-1.png) - **Patch Deployment list**: This report will list the configuration through which patches are published to the Self-Service Portal. ![Self-Service Portal patch report](https://www.manageengine.com/products/desktop-central/help/images/ssp-report-2.png) - **Detailed View**: This report lists all the details of the patches which are published to the Self-Service Portal. ![Self-Service Portal patch report](https://www.manageengine.com/products/desktop-central/help/images/ssp-report-3.png) ## Related - [Audit & Reports](https://www.manageengine.com/desktop-management-msp/help/patch-management/executive-reports.html)