Query version of a report 'Compliance 3 - Update Group (per update)'

Hi,
I was wondering if it was possible to create a query where I can view number of missing updates based on
my baseline. This will be similar to an existing report 'Compliance 3 - Update Group (per update)' and when I select a collection, I would expect it to show me the results similar to the report itself.
Example:
Title Bulletin ID
  Installed Required
Security Update for Windows Server 2008 R2 x64 Edition (KB2977292)
  0 145
Security Update for Windows Server 2008 R2 x64 Edition (KB2984972)
  0 145
Security Update for Windows Server 2008 R2 x64 Edition (KB3002885)
MS14-079   0
144
Thanks.
144

I'm not totally following what you're asking but why not create a new software update group (no deployments necessary) containing the same updates as in your baseline? This type of update group is informally called a compliance group. That way,
you just run the report you've called out against this compliance group.
Jason | http://blog.configmgrftw.com | @jasonsandys
This is purely for reporting purposes as we currently have a problem with Reporting Services. I thought I could create a query which will list the updates we have compiles in software update group and show how many servers require that update within limited
collection I will select on the query.
Thanks.

Similar Messages

  • Software update group - Superseded updates

    Hi all,
    I need to understand something. I have Software Update Group and it has a deployment configured . When a given update becomes superseded and I remove it from the software update group, how does this affect the configured deployment? I don't
    want to delete/recreate the deployment.  Will the deployment automatically update itself and remove the update that I removed from the Update Group, will it still try to deploy the upddate...wil it give an error...etc.
    Thanks in advance,
    Jesmat.

    The deployment is for the updates in the software update group. For currently targeted devices it will need a machine policy update before they know about the change.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Limit 'Specific computer' report to a Software Update Group

    I'm trying to get the SCCM 2012 report 'Compliance 5 - Specific computer' limited to an updae group rather than reporting against every applicable patch.
    In the environment I'm working in we are only interested in reporting on compliance against an agreed list of 'released' updates (we don't release all updates to our server estate). When you start reporting with the 'Compliance 1  - Overall compliance'
    we can select our 'master' software update group here and get the correct compliance status. We can then drillthrough these status into the next report, 'Compliance 7' and the update group is passed through into this report along with the collection and relevant
    status.
    However when we drillthrough to the next report, 'Compliance 5 - Specific computer', the update group is not passed through or used in this report so we get a compliance status for the specific computer against every update. I want to use the update group
    in the last report to limit what's returned here.
    Can anyone help with this? I'm lacking the SQL expertise to be able to add the relevant code to the last report.

    I think you're looking for the Compliance 3 - Update group (per update) report. In this report you can select an update group and a collection and the report will return the compliance data of that combination.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude
    The report 'Compliance 3..' is a summary report for each patch against a collection. This is completely different from I'm trying to achieve which is a detailed breakdown of compliance against each patch in an update group for a specific computer.

  • Best practice in getting compliance rates of Software Update Deployments

    Hi,
    Would like to ask around on how others generate reports about software update deployment compliance. What do you use to get this report? Are there best practices for gathering software update compliance reports?

    There is not really a best-practice on reports that you need to use for compliancy on software updates. One of the reports I often use to check the compliancy is
    Compliance 1 - Overall compliance as it provides a good overview of a specific collection for an update group. For more details you can use
    Compliance 3 - Update group (per update).
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Update showing up in "Compliance 5 - Specific Computer" Report even after removing the update from the Software Update before creating Group and Package

    So I've created a Software Update Group and I did NOT want anything in there dealing with Internet Explorer 11 since the organization is currently stuck at using 10 as the highest. So I made sure that Internet Explorer was NOT in the list and then I deployed
    the package. 
    After running my Overall Compliance report it shows that the systems are compliant, but when I view the "Compliance 5 - Specific Computer" I see that "Internet Explorer 11 for Windows 7 for x64-based Systems" is listed in the report. 
    This is just a testing phase right now and I have not created a WSUS like Domain level GPO. I understand that the SCCM client creates a local policy on the clients for the location of the Software Update Point (Specify
    Intranet Microsoft update service location), but the "Configure Automatic Updates" policy is set to Not Configured, which it looks like when this
    is set, the "Install updates automatically (recommended)" at 3AM is the default. 
    Is the reason why the "Internet Explorer 11 for Windows 7 for x64-based Systems" update is showing up in the list due to the fact that the "Configure
    Automatic Updates" policy is set to Not Configured
    and therefore it is still reaching out to check Windows Update online? 
    So, if I do create a Domain level GPO to Disable the "Configure
    Automatic Updates" policy, then the "Internet Explorer 11 for Windows 7 for x64-based Systems" update would not show up in the "Compliance 5 - Specific Computer" report?
    By the way, I have a Software Update Maintenance Window configured for the hours of 1AM-4AM so the 3AM default time falls within this time frame, therefore, I am assuming the SCCM 2012 client will not allow the Windows Update Agent to install the "Internet
    Explorer 11 for Windows 7 for x64-based Systems" update, even though it has detected it is "Required". 
    Thanks

    But, don't you need a Deployment Package in order to deploy the Software Update Group? The Software Update Group uses the downloaded updates contained in the Deployment Package located in, wherever the Package Source is, right?
    One more quick question that you will know right off hand, because, well, you just will I'm sure.
    No. The software update group really has nothing to do with any update packages. The update group assigns updates to clients and in turn clients use update packages to download assign and applicable updates from. There is no connection between the two though
    as the client can download an update from any available update package. Thus, it's more than possible to updates in an update package that are not in any update groups and it is also possible for an update to be in an update group without being in any update
    package.
    If the "Configure Automatic Updates" policy is set to "Not Configured" and since this keeps the 3AM Automatic Updates default, if I was to remove the Software Update Maintenance Window from being between 1AM-4AM, will the WUA agent install updates
    at 3AM, or no because the SCCM 2012 client still manages and oversees it and basically blocks that from occurring?
    No, ConfigMgr does not in any way block the WUA; however, the WUA can only autonomously install updates it downloads directly from WSUS. Thus, since there are no updates approved or downloaded in your WSUS instance, there's nothing for it to download and
    install. If you happen to actually be going into WSUS and approving updates (which you should not be doing as its unsupported), then yes, it actually would install updates -- this is outside of ConfigMgr's control though. Generally, disabling the WUA via a
    GPO is the recommended to prevent any accidental installations or reboots (as the WUA wil also check for initiate pending reboots outside of ConfigMgr).
    Lots more info in these two blog posts:
    - http://blog.configmgrftw.com/software-update-management-and-group-policy-for-configmgr-what-else/
    - http://blog.configmgrftw.com/software-updates-management-and-group-policy-for-configmgr-cont/
    Jason | http://blog.configmgrftw.com

  • LIS (Report: MCTE) is not getting updated

    Dear All,
    We have created a New Profit/ Cost Center and then created a Substitution Rule, based up on Sales Org+Dist ChnlDivision+Sales Office_
    Then we have created delivery and then Invoicing. Accounting Document has been generated and G/L A/Cs have been hit, accordingly.
    Now, when we refer to Standard Report: MCTE, (for above said Sales Area), Report shows No data for chosen criteria.
    Here, I would like to mention that all required configuration for LIS Updation,
    SPRO --> IMG --> Logistics-General --> LIS --> Logistics Data Warehouse --> Updating --> Updating Control --> Settings: Sales --> Update Group
    --> Assign Update Group at Item Level
    --> Assign Update Group at Header Level
    have already been maintained before Sales Order Creation.
    Moreover, the same config-settings is working fine at our Quality-Server, whereas, Its not working on to PRD-Server.
    Couls anybody suggest, some more checks to perform?
    Best Regards,
    Amit

    Hi Amit,
    When you moved your changes to Production Server and then after you have created a document for the above mentioned Sales Area. Now is this document also not coming up in the Report?
    If yes then can you please tell me what value has got Updated in the Database Table both at Header and Item level in the Field Update group.?
    Madhukar.

  • SCCM 2012: Assigned updates to update group don't get there deployment

    Hello,
    Problem:
    When I assign available updates to the update group the updates are not getting there deployment. Deployed: NO
    (Previous months no problem)
    Situation:
    SCCM 2012 SP1
    We made different Update groups. Example:
    Windows 2008 R2
    This group is deployed to different collections and has several deployments.
    Steps taken:
    Downloaded the new updates to Windows 2008 R2 Deployment Package (no errors)
    Edit Membership and added updates to the Windows 2008 R2 update group (no errors)
    When I check the update group I see the assigned updates in the group. The Downloaded Status is YES but the Deployed status is NO. When I check the update deploymensts it has no deployments.
    Any idea where to find a solution for the problem? Which logs files to check? 
    Greetings

    You could try and run this sql query to check the database directly and see if IsDeployed = 1 here. If that is the case there is just the console that is not updated. You'll need to change the Config Item ID (in red) to match the ID of your group, you'll
    find this in the console. (Right click columns and add it)
    select  all upd.CI_ID,upd.LocaleID,upd.ApplicabilityCondition,upd.ArticleID,upd.BulletinID,upd.CI_ID,upd.CI_UniqueID,upd.CIType_ID,upd.CIVersion,upd.CreatedBy,upd.CustomSeverity,upd.CustomSeverityName,upd.DateCreated,upd.DateLastModified,upd.DatePosted,upd.DateRevised,upd.EffectiveDate,upd.EULAAccepted,upd.EULAExists,upd.EULASignoffDate,upd.EULASignoffUser,upd.IsUserCI,upd.InUse,upd.IsBroken,upd.IsBundle,upd.IsChild,upd.IsContentProvisioned,upd.IsDeployable,upd.IsDeployed,upd.IsEnabled,upd.IsExpired,upd.IsHidden,upd.IsLatest,upd.IsMetadataOnlyUpdate,upd.IsOfflineServiceable,upd.IsQuarantined,upd.IsSuperseded,upd.IsUserDefined,upd.LastModifiedBy,upd.LastStatusTime,upd.Description,upd.DisplayName,upd.CIInformativeURL,upd.LocaleID,upd.MaxExecutionTime,upd.ModelID,upd.ModelName,upd.NumMissing,upd.NumNotApplicable,upd.NumPresent,upd.NumTotal,upd.NumUnknown,upd.PercentCompliant,upd.PermittedUses,upd.PlatformType,upd.RequiresExclusiveHandling,upd.RevisionNumber,upd.SDMPackageVersion,upd.SedoObjectVersion,upd.Severity,upd.SeverityName,upd.SourceSite
    from fn_ListUpdateCIs(1033) as upd,vSMS_CIRelation as cr  where ((cr.FromCIID =
    16822104
    AND cr.RelationType = 1) AND upd.CI_ID = cr.ToCIID)

  • About update group in credit management

    can any one help of what is the exact work of update group what type of advanatage we get wwhile using update group for ex: 000012,000015,000018.
    it is given that for 000012  sales order: increases openitems for orders for delivery relevant schedule lines.
    how the system increases the open items for sales orders under update group 000012

    Hi
    Update groups are used, in order to group different key figures from (e.g) SD module to the structures in Logistics Information System.
    What happens is when ever an event take place, e.g billing document raised, it can be customized to populate the LIS Structure (kind of a data warehouse) with key data you are looking for to report and evaluate. This update can be made either immediately or periodically.
    The credit relevant data is updated into an information structure, where it is accessed andupdated. Thus each automatic credit control must be assigned an update group. The system allowsfor no update, and update group 000012, 000015 and 000018.
    The difference between the three update groups is as follows:
    Update group 000012
    Sales order: Increases the open order value from delivery-relevant schedule lines
    Delivery: Reduces the open order value from delivery-relevant schedule lines and increases the open delivery value
    Billing document: Reduces the open delivery value and increases the open billing document value
    Financial accounting document: Reduces the open billing document value and increases open items
    Update group 000015
    Delivery: Increases the open delivery value and increases the open billing document value
    Financial accounting document: Reduces the open billing document value and increases open items
    Update group 000018
    Sales order: Increases the open delivery value
    Billing document: Reduces the open delivery value and increases the open billing document value
    Financial accounting document: Reduces the open billing document value and increases open items
    The decision on which update group to use is based upon the business requirements; however,
    update group 000012 is thorough and used in most businesses.

  • Update group in automatic credit control

    Hi Everybody,
    Can anyone explain me the meaning of update group in automatic credit control screen OVA8.
    Do we have to set this update or it happens when we start usinng?
    Regards,
    raghu

    Hi,
    More info on this ,
    <b>Credit update for open order/delivery/billing document value</b>
    The credit update controls when the values of open sales orders, deliveries, and billing documents are updated.
    Note
    The open order value is only updated for schedule lines that are relevant for delivery.
    Use
    You can specify the following update groups for updating credit-related statistics:
    <b>Update group 000012</b>
    Sales order
    Increases open order value from delivery-relevant schedule lines
    Delivery
    Reduces open order value from delivery-relevant schedule lines
    Increases open delivery value
    Billing document
    Reduces open delivery value
    Increases open billing document value
    Financial accounting document
    Reduces open billing document value
    Increases open items
    Update group 000015
    Delivery
    Increases open delivery value
    Increases open billing document value
    Financial accounting document
    Reduces open billing document value
    Increases open items
    Update group 000018
    Sales order
    Increases open delivery value
    Billing document
    Reduces open delivery value
    Increases open billing document value
    Financial accounting document
    Reduces open billing document value
    Increases open items
    <b>Note</b>
    If a document cannot be processed with the update group you specify, the system determines the next possible update it can carry out. For example, you select Update group 000012 which, at delivery, reduces the open order value and increases the open delivery value. Assume that one item in the order is not relevant for delivery. In this case, the system automatically determines Update group 000018 for this item. Update group 000018 increases the open delivery value for the order item. The system uses the confirmed quantity of delivery-relevant schedule lines to update the order value.
    Hope it adds. Pl reward if helpful.
    Thanks & Regards
    Sadhu Kishore

  • Update groups in Automatic Credit Mgmt..

    Hi Gurus,
    What is the significance of the various update groups present in Automatic Credit Mgmt.
    When do we have to choose 12 ,15 and 18 type  of update groups.
    Where do we assign the same.
    Sure to reward points for satisfactory answers
    Cheerzz..
    Subbz..

    Hi Subba,
    Update group is defined /assigned in Credit Control Area Defination (path:IMG>ENTERPRISE STRUCTURE>DEFINITION>FINANCIAL ACCOUNTING>DEFINE CREDIT CONTROL AREA).
    Whatever is defined for this field  here gets reflected in the OVA8 screen.
    There are 3 types of update groups:
    1) update 000012 - open order on time axis, delivery and billing doc value. It means during automatic credit check the system compares the customer's credit limit to the total of open orders as well as the deliveries and billing doc value
    2. update 000015 - open deliveries and billing doc value.  It means during automatic credit check the system compares the customer's credit limit  to the total of open deliveries as well as the  billing doc value
    3. update 000018 - open delivery for sales orders, billing doc value.
    Hope u ve undrstood.
    plz reward points if helpful
    Regds,
    Pallavi

  • Deployment Package vs Right-Click, Deploy directly from Software Update Groups?

    I'm not sure I understand the difference between collecting updates into a group and then just using right-click to create a deployment from within Software Update Groups?
    One thing I did notice this morning, is that if I want to distribute that content to other DPS, I have to create deployment package first? Are there other reasons for not simply deploying from within Software Update Groups?
    Thank-you

    Update Groups *group* updates together. That's it, they have no additional functionality.
    Updates can be deployed individually or as groups (in the form of Update Groups) -- it would be pretty painful to manually deploy every update individually so that's why there are update groups.
    Update Packages (I don't like calling them deployment packages even though that's what they're labeled as in the console because they have nothing to do with deployments) make update binaries available to the clients.
    Update Groups have nothing to do with Update Packages. Update Groups contain references to updates, update packages contain binaries. Deploying an update or update group assigns those updates to the client within the collection specified. Clients that have
    an update assigned that is also applicable will download the binary for the update from any available update package and install it.
    You create an update package by right-clicking on an update or update group and choosing download. The wizard offers you a choice between using an existing package or creating a new one. You cannot directly create on.
    Secondary sites have nothing to do with this process whatsoever. Clients are clients are clients regardless of where they are located. As long as they are within t he collection targeted by the deployment and they have access to the assigned update binaries
    in an update package, they will download and install the updates properly.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Report of total invoice per area

    Dear Experts,
    I am trying to make a report using query generator. The report is total invoice per area but I am still failed. here is the query I made:
    elect distinct OTER.descript,
    'invoice per teritory' = (select distinct sum(a.DocTotal) from oinv a inner join ocrd b on b.cardcode = a.CardCode where a.CardCode = OINV.CardCode and b.County = OCRD.County group by b.County) from INV1 inner join OINV on OINV.DocEntry =
    INV1.DocEntry
    INNER JOIN OCRD on OCRD.CardCode=OINV.CardCode
         LEFT JOIN OTER on OTER.territryID=OCRD.Territory
    where OINV.DocDate between '01/01/2010' and '01/28/2010'
    The result is as follows:
    Area A     47533700.000222
    Area A     53663149.964662
    Area B     772500.000010
    Area B     6705000.000072
    Area C     7890000.901213
    It is not expected.
    I am using query generator is :
    Area A     101196850
    Area B     7477500
    Area C     7890000.901213
    but my query still give unexpected result. Please advice. Thanks a lot.
    steve

    Thx Gordon.
    This thread is closed. I also find out the answer i.e.
    select distinct OTER.descript,
    'invoice per teritory' = (select distinct sum(a.DocTotal) from oinv a inner join OCRD b on b.CardCode = a.CardCode where
    b.Territory = OTER.territryID  group by b.Territory) from OINV
    INNER JOIN OCRD on OCRD.CardCode=OINV.CardCode
         LEFT JOIN OTER on OTER.territryID=OCRD.Territory
    where OINV.DocDate between '01/01/2010' and '01/28/2010'
    group by OTER.descript, OTER.territryID
    The result is similar with your query result.
    Steve.

  • Compliance based on Update Group Statistics

    Hello,
    I am confused about the "Statistics" looking at a Software Update Group. I have two groups, One for IE9, the other for IE10. Yesterday the IE9 group showed 80% (guessing looking at the chart graphic), then I pulled in IE10 updates and made a new
    group. Now the IE9 group shows 14% compliant, and the IE10 group shows 76% compliant. Problem is I applied the updates to two different collections and right now all Windows 7+ get the automatically added to the IE9 group, so 3000+ clients, and the
    IE10 group is manual, with 2 computers.
    Now I understand that the chart shows overall compliancy instead of just the collection, but why am I now 76% complient on IE10 and not really compliant on IE9? I should be less compliant on IE10.
    Someones insight on this would be helpful.
    Thanks!

    Also an addition. I found a thread on WindowsNoob about getting data out of v_GS_Installed_Executable. From what I can tell this is part of the hardware inventory, but when I look at the contents of the table it is empty. I do have hardware inventory enabled
    on clients too.
    I was looking for a report to show version of IE installed, which I was able to use v_GS_SoftwareFile to get the data since I am tracking *.exe in the database. Just curious why v_GS_Installed_Executable is empty, when by my understanding, it should have
    data.

  • Collections based on Software Update Group compliance

    Hi!
    Is it possible to create a collection based on software update group compliance? This is for software update groups which are
    not deployed, they are just monitor groups (for example, groups for yearly or quarterly software update compliance).
    I would like to create a collection that lists all devices which are non-compliant in software update groups with names like "%Client Updates" - is this possible?
    The reason for this is so I can impose some stricter Compliance Settings (among some other stuff) on devices that are not compliant.
    I looked around a bit, but I could not find anything that I can use. Even Google couldn't solve my question :/

    you can try something like this:
    This collection is basically sub selected query get list of computers that do not have specific assignment enabled.
    select *  from  SMS_R_System where SMS_R_System.ResourceId not in (SELECT distinct SMS_UpdateComplianceStatus.MachineID  FROM SMS_UpdateComplianceStatus JOIN SMS_UpdateDeploymentSummary ON SMS_UpdateComplianceStatus.CI_ID = SMS_UpdateDeploymentSummary.CI_ID
    WHERE SMS_UpdateDeploymentSummary.AssignmentName like "%Client Updates%")
    Eswar Koneti | Configmgr blog:
    www.eskonr.com | Linkedin: Eswar Koneti
    | Twitter: Eskonr

  • What Changes to Software Update Group Causes Clients to Re-check Compliance

    Hello,
    I have a number of software update groups that have been deployed over the past couple of years. When Microsoft release new updates etc. some of the updates already deployed change their status e.g. an update might get marked as expired. As a result of this
    I can go from having clients reporting as being compliant to a situation where they are in an unknown state until they report back again.
    Does anyone know what changes to an update already deployed would cause clients to have to check their compliance status for that software update group?
    Thank you.
    Stephen

    If you are referring to the enforcement state, this is indeed specific to the deployment, not the group itself.
    With regards to your question - Upon a change to your deployment, your clients will receive updated policy.  On a successful evaluation of the deployment, it will re-send a state message if necessary.  Unfortunately I do not know if there are certain
    things that do not trigger a policy update (i.e. change in the name or description vs. update membership or deadline change)

Maybe you are looking for

  • Blue Screen of Death when calling skype on iphone/s6

    Every time i call a person on skype on iphone or s6 (i think any smartphone) my computer crashes and causes blue screen of death. i have windows 8.1 running and this also happened on win 8. i have tried uninstalling, clean installing, deleting all ol

  • What height is a floor in health app

    II'm puzzled what the Health App measures to be a 'floor'.  I'm in the UK and when I'm working from home and don't have time to train outside I walk my house stairs  a number of times. This morning I walked a series of 10 up and downs. Followed later

  • How to send video longer than 1 minute?

    I'd like to send some video to youtube that is longer than a minute. As far as I can tell, this is impossible...? OR, if this cannot be done, can I edit my video down? (sorry, I briefly searched this topic and didn't see anything right away). Thanks!

  • Creating Dynamic Internal table with a dynamic name

    Hi, I want to create dynamic internal tables with dynamic names. For example: Suppose I have a table with three fields. 1. Structure name 2.Fields 3.file And the structure of the internal table is as follows: TYPES:BEGIN OF table_type,       struct  

  • Rename file at FTP

    Hi All I have written a module in which i am checking wheather the file is duplicate or not - this is successfully done. What my new task is i have to include a code in this module that --- if the file is duplicate rename the file. How can i achieve