Skip to main content

Patch

The Patch tab shows the patch state of the machine and lets you deploy or roll back patches. It has three sub-sections: Missing, Installed, and Exception.

How to get here

Open an endpoint (see Summary), then click the Patch tab.

URL path: /inventory/endpoints/{id}?tab=patch

Columns

All three sub-sections share these columns:

ColumnWhat it shows
IDThe patch ID (links to its detail).
TitleThe patch title (links out).
SeverityPatch severity.
PlatformOS it applies to.
Release DateWhen it was released.
RollbackWhether it can be rolled back.
CategoryPatch category.
KBIDKnowledge-base ID (links to the vendor article).

Hidden by default: UUID, Patch Approval Status, Patch Test Status, and (on Exception) Exception Reason.

Missing

Patches not yet installed.

The Patch tab on the Missing sub-sectionThe Patch tab on the Missing sub-section

Select rows and click Install to deploy them. Add Exceptions excludes a patch from this machine.

Installed

Patches already applied.

The Patch tab on the Installed sub-sectionThe Patch tab on the Installed sub-section

Select rows and click Rollback to remove them (where the patch supports it).

Exception

Patches you've excluded, with the Exception Reason.

The Patch tab on the Exception sub-sectionThe Patch tab on the Exception sub-section

Toolbar

Across all three: the Last Scan time, Scan Now (re-scan this machine), and Scan History (a drawer of past scans).

Tips & troubleshooting

  • A patch keeps showing under Missing. Deploy it with Install, or exclude it with Add Exceptions if it shouldn't apply here.
  • Counts look stale. Click Scan Now, then check Scan History for the result.
Install, Rollback, and Exceptions change the endpoint

Install and Rollback act on this live machine and may trigger a reboot. Rollback works only where the Rollback column says it's supported, and it removes an applied patch. Add Exceptions stops a patch from ever applying here until you remove the exception- use it deliberately, not to clear a stuck row.

  • Patches- the fleet-wide Patch module, the same patches across every endpoint.
  • Vulnerabilities- what these patches remediate.
  • Summary- the screen these tabs live on.