About Operational Status

The Operational Status page provides you a consolidated view of the patching posture of your subscription. It brings together asset activation, asset health, service level agreement (SLA) compliance, deployment results, and patch effectiveness in a single view.

Each card on the page displays a dynamic count that is calculated from your own subscription data. These numbers are categorized as per the Windows, Mac, and Linux operating systems. Most counts are clickable, that redirect you to the underlying list of assets or patches. The page is made up of a fixed set of default cards. Unlike Dashboards, you cannot add, remove, or edit the cards on this page. You can, however, narrow what each card reports by using the duration, platform, SLA, and search filters that the cards provide. 

The data shown on this page is specific to your subscription. The counts you see are restricted to the assets that are within your assigned scope.

The Operational Status page is available on the Home tab, alongside the Overview tab. 

Asset Activation Summary

The Asset Activation Summary section reports how many of your assets are ready for patching. It contains the following two cards:

  • Asset Enabled for Patch DeploymentThe number of assets in your subscription on which patches can be deployed, because the asset has Patch Management license and is activated for the same.
  • Asset Enabled for Patch ScansThe number of assets in your subscription that are eligible to be scanned for missing patches. These assets must be activated for Patch Management asset.

Each card shows a total count, a doughnut chart, and a breakdown of that count by Windows, Mac, and Linux platforms.

Assets are activated for patching through the Cloud Agent, by activating the Patch Management application on the agent. There is no separate activation step for patch scans. Once the Patch Management application is activated on an asset, that asset becomes applicable for both patch deployment and patch scans, which is why the two cards commonly report the same total. For more information, Installing Cloud Agents for PM.

Asset Health Status

The Asset Health Status section identifies activated assets that are not behaving as expected, so that you can investigate them before they fall out of compliance. Use the Duration filter at the top of the section to set the evaluation window. The available options include Today, Yesterday, Last 7 Days, and Last 30 Days.

This section contains the following three cards:

  • Asset Not Running Patch Job: Assets on which no patch job has run within the selected duration.
  • Asset Not Running Patch Scans: Assets on which no patch scan has run within the selected duration.
  • Asset Not Communicating with Qualys: Assets that hold a Patch Management license but have not communicated with the Qualys Cloud Platform within the selected duration. An asset can appear here when the agent has stopped reporting, for example because the host is powered off, is offline, or has stopped scanning.

Each card shows a total count, a doughnut chart, and a breakdown by Windows, Mac, and Linux. Hover over the information icon on a card to view a short description of what that card measures.

The duration filter identifies assets by absence of activity rather than presence of activity. When you select Last  7 Days, the card lists every asset that has not run the relevant activity at any point up to seven days ago - it does not list only the activity that occurred within the last seven days. An asset that has never run a patch job is therefore included in the count.

SLA Violation Status

The SLA Violation Status section shows how many of your assets are carrying patches that have remained unapplied for longer than the SLA you define. This lets you measure your environment against your own remediation commitment rather than against a fixed Qualys default.

Configure the section using the following controls:

  • SLA: Enter a numeric value and select the value, either Day(s) or Month(s). The maximum permitted values are 365 days and 12 months. Values above these limits are not accepted.
  • Patches search field: Enter Qualys Query Language (QQL) tokens to restrict the calculation to specific patches, for example a particular patch family or vendor.
  • Assets search field: Enter QQL tokens to restrict the calculation to specific assets, for example by operating system.

The Assets with SLA Violation card then reports the number of violating assets against the total number of assets, together with the breakdown by Windows, Mac, and Linux. The description below the count restates the SLA currently in effect, for example, Assets with at least one missing patch beyond 1 day of patch publication.


- An asset is counted as violating the SLA if at least one of its missing patches was published earlier than the SLA window. It is not necessary for every missing patch on the asset to breach the SLA. For example, if an asset is missing 100 patches and only one of those patches was published before the SLA cut-off date, that asset is still counted as an SLA violation.
- By default, the card reports across the whole of your subscription. As soon as you apply a QQL token in either search field, the count is recalculated for the filtered scope only. Selecting a token from the token list appends it to the query that is already in the field, rather than replacing it.

Deployment Status

The Deployment Status section reports the outcome of the remediation work that has actually run in your environment. Use the filters at the top of the section to scope the results:

  • Duration: Sets the time window for the deployment results, for example, Today.
  • Tag filter: Restricts results to assets carrying the selected tag, for example, Cloud Agent.
  • Platform: Restricts results to a single operating system, for example, Windows.

The section is divided into the following two parts:

Patch Deployment

This part reports the outcome of standard patch deployments and contains the following cards:

  • Total Deployed Patches: The total number of patches deployed within the selected scope.
  • Successfully Deployed Patches: The percentage of those patches that installed successfully. Use the Report option on this card to download the supporting detail. You can select the columns you want to generate in the report.
  • Failed Patches: The percentage of those patches that failed to install. Use the Report option on this card to download the supporting detail. You can select the columns you want to generate in the report.

A ratio bar above the cards shows the success-to-failure split visually, using green for successfully deployed patches and red for failed patches.

Permanent Fix Deployment Status for No Patch Vulnerabilities

Some vulnerabilities cannot be resolved by installing a vendor patch, because no patch exists. For these, a permanent fix, such as a configuration change or a registry change is applied instead. This part reports the outcome of those fixes and contains the following cards:

  • Total Deployed Permanent Fixes: The total number of permanent fixes deployed within the selected scope.
  • Successfully Deployed Permanent Fixes: The percentage of those fixes that applied successfully.
  • Failed Fixes: The percentage of those fixes that failed to apply.

Hover over the information icon next to the heading to view a short description of what qualifies as a no-patch vulnerability.

Navigation from Cards

Most values on the Operational Status page act as entry points into the detailed data. Note the following about navigation behavior:

  • Click an operating system count on a card. For example, the Linux count on the Asset Enabled for Patch Deployment card to open the corresponding list with a query already applied. The list opens on the tab for that operating system.
  • Click the doughnut chart on a card to open the corresponding detailed list.
  • When a count is zero, the target list opens with no records. When a card has no data at all, the doughnut chart is not clickable.

Related Topics

Risk Elimination Overview

Reviewing Missing and Installed Windows Patches

Reviewing Missing Patches for Linux Assets