Working together · 5 min read
How to read your monthly IT report
Your report is not just a list of tickets. Here is how to get real value from it in five minutes.

Every monitored client gets a monthly report. It exists so you can see what you are paying for without having to ask, and so that patterns get spotted before they become expensive. It takes about five minutes to read properly, and this is how to do that.
The summary
The opening summary is the part to read if you read nothing else. It covers what happened across the month in plain English: how much was handled, what needed attention, and anything I want you to be aware of. If something needs a decision from you, it will be here.
Alerts, and why most of them never reached you
Alerts fall into three groups:
- Resolved automatically. Raised and cleared by monitoring within a few minutes, with no user impact. These are noise, and they are listed for completeness only.
- Routine maintenance. Alerts that occurred entirely out of hours as part of scheduled work. No action was required.
- Actioned. Something I looked at and fixed. These are the ones worth reading.
A large number of alerts is not automatically bad. A large number of actioned alerts on the same device month after month is the thing to notice.
Alert types in plain English
- Disk space. A drive filling up. See the article on what is safe to delete.
- Uptime. A machine that has not been restarted for too long.
- Performance. CPU, memory or network usage running high.
- Service. A background Windows service that stopped and needed restarting.
- Event log. Something logged by Windows that warranted a human look.
- Availability. A device that dropped off the network.
- Security. A threat detection, with a risk level attached.
Support activity
This section covers the human work: calls, remote sessions, on-site visits and the time attached to each. It is worth scanning for two things. First, whether the same person or the same issue keeps appearing, which usually means training or a hardware change would be cheaper than continued support. Second, whether the work matches what you expected, because if it does not, I would rather know in month two than month twelve.
The questions worth asking
- Which device generated the most alerts, and should it be replaced?
- Are the same issues recurring, and what would stop them permanently?
- Is anything on here a symptom of something we have not addressed yet?
- Is there work we keep deferring that is now costing more in support time than it would to fix?
Ask me these. That conversation is the point of the report.
What the report is not
It is not a bill justification exercise, and it is not a scorecard. Some months are quiet. A quiet month with few actioned alerts means the preventative work is doing its job, which is exactly what you want to be paying for.
If you would like a walk through your last report, or you are not currently getting one and think you should be, get in touch.
Need a hand with this?
I help small organisations across the UK with exactly this kind of work. Honest advice, plain English, no pressure.
Get in touch