Session Relevance to filter Patches for Windows, Security* fixlets

I need to produce a simple text report for change management purposes. At the beginning of patching cycle, what fixlets in the current base are applicable on what endpoints?

I can obtain a list of endpoints and ALL fixlets relevant, including pending restarts and other custom items I do not want in the report.

I’ve missed the mark enough times, I’ll just ask the community for help…or a pointer at relevant post with suitable syntax. How can I modify the below, functional session relevance to only include fixlets with category starting with “Security” of the “Patches for Windows” site.

(item 1 of item 1 of it, item 0 of item 1 of it) of (names of it, (names of it, names of applicable computers whose (it is contained by set of members of bes computer groups whose (name of it = "GROUPNAME")) of it) of source fixlets of components of component groups of it)of bes fixlets whose (baseline flag of it and name of it = "BASELINENAME")

components whose (category of source fixlet of it starts with “Security”)

Apologies, answer very brief, I’m typing this on my phone

That was the ticket.

(item 1 of item 1 of it, item 0 of item 1 of it) of (names of it, (names of it, names of applicable computers whose (it is contained by set of members of bes computer groups whose (name of it = "GROUP")) of it) of source fixlets of components whose (category of source fixlet of it starts with "Security") of component groups of it) of bes fixlets whose (baseline flag of it and name of it = "BASELINE")