I usually create a SQL query and apply that to a new COLLECTION that has the specific purpose of holding all computer accounts that adhere to the SQL query parameters.

For my organization, I've created a toplevel collection called, "_App Installations". Under that I have 2nd level collection containers that I name for each program I intend on upgrading/installing. The 3rd level collection container is specific to a certain upgrade/installation for that program.

So for example: I have a collection tree as follows - _App Installation>Symantec>Clients Needing AV 10.0.2.2020 Patch

I create an SQL query that searches the results of each computer's Hardware Inventory. Based on the query, all computers that do not have Symantec AV version 10.0.2.2020 but DO have version 10.0.2.2000 are members of this collection.

I then create a new program package based on the Symantec Patch ( I think it was an MSI so I used the package creation wizard), and then I assign an advertisement to the "Clients Needing AV 10.0.2.2020 Patch" collection.

I know the collection tree is a little deep being three layers for this patch, but when you're looking at deploying a lot of applications it helps to organize them in a way that is easy to traverse, and is logical.

Sometimes you'll find that you want to change the frequency of hardware inventory or require a full hardware inventory after a package is deployed in order to keep the membership of your software deployment collection up to date.

I hope that helps!
_________________________
let the wise listen and add to their learning,
and let the discerning get guidance- Proverbs 1:5