The Patch Management Solution for IT Management Suite (ITMS) provides detailed reports to track patch deployment compliance. However, the terminology used in reports like "Software Bulletin Details" (under the SMP Console: Home>Patch Management> Bulletins and Updates) and "Windows Compliance by Bulletin" (under the SMP Console: Home>Patch Management> Compliance by Bulletin) can sometimes be confusing. Understanding the meaning of key report columns like Applicable, Applies To, Installed (Count), and Not Installed (Count), and how they relate to the client's internal patch status is crucial for accurate compliance reporting.
This article clarifies the meaning of key patch status columns, such as Applicable, Applies To, Installed (Count), and Not Installed (Count), and recommends using the more straightforward "Compliance by" reports for a clear compliance overview.
IT Management Suite (ITMS)
Patch Management Solution for Windows or Linux operating systems.
The Patch Management Solution relies on a multi-step workflow where client computers determine their own patch requirement status. The compliance columns in the console reports are a direct result of the Applicability Scan and the Compliance/Installed Scan results reported back from managed computers.
The Patch Management Solution uses an Applicability Scan (Windows System Assessment Scan (WSAS)) to determine which managed computers are applicable to a specific software update (patch,) and if applicable, is it installed, effectively installed, or missing. The report columns are a direct reflection of the data collected during this scan and the subsequent deployment status.
The column names derive from internal logic:
Understanding this workflow is key to interpreting the report data. This process ensures that computers are only targeted with patches they truly need.
Core Checks: The client verifies:
Result:
The mentioned reports below can be accessed under Home > Patch Management
The columns provide two different perspectives on the patch status:
|
Column Name |
Report Location |
Meaning (What does it count?) |
Patch Status Check |
|
Applies To |
"Software Bulletin Details" |
The total number of unique computers that the patch's applicability rules determined may need this update. This count is for all discovered patches for a given bulletin. |
Applicability (Is this patch necessary / could apply?) |
|
Applicable |
"Compliance by Bulletin" |
The number of computers that the patch's applicability rules determined need this update. (Equivalent to Applies To in the other report). |
Applicability (Is this patch necessary?) |
|
Installed (Count) |
"Compliance by Bulletin" |
The number of computers where the patch's installed rules determined the update has been successfully applied, has had a superseding update installed, or otherwise does not need to actually install the update. |
Installed Status (Is the patch or superseding patch installed?) |
|
Not Installed (Count) |
"Compliance by Bulletin" |
The number of computers that are Applicable but where the patch's installed rules determined the update is not yet present. This is your primary metric for non-compliance. |
Installed Status (Is the patch missing?) |
|
Updates |
"Software Bulletin Details" |
The total number of individual patches (Software Update resources) within a single Bulletin. A Bulletin may contain one or many individual patches. |
Metadata (How many patches in the bulletin?) |
|
Available |
"Software Bulletin Details" |
The total number of patches that have been successfully downloaded and are ready for deployment. |
Readiness (Is the patch ready to deploy?) |
For management and compliance tracking, it is strongly recommended to use the "Compliance by Bulletin" or "Compliance by Computer" reports.
These reports use the Compliance Percentage which is calculated as:
This provides the most accurate and easily understandable metric for your patching success.
For additional troubleshooting and related information, refer to these Knowledge Base articles:
How a patch is determined to be Installed on a computer
Patch Compliance Status does not seem to match the report data
Patch Management Solution: Understanding Patch Statuses and how they are calculated in the Console
Is the Installed column in the Compliance by Bulletin report accurate?
Software Updates failing to deploy in Patch Management v8.x (Workflow and Troubleshooting)
Definitions for each main Software Update status in IT Management Suite