---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Incident diagnostics and suggested resolutions

# Incident investigation with DEX {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read  
Service desk agents can diagnose and resolve issues for Digital End-User Experience (DEX) monitored devices from an incident record by using DEX diagnostics and suggested resolutions.  
Incident investigation with DEX provides a comprehensive view of device and application health metrics, issue diagnosis, and suggested resolutions. It helps identify and resolve common device and application issues, leading to faster incident resolution and enhanced service desk experience.  
Important:  
Incident investigation with DEX is available from the Zurich release and requires Service Operations Workspace for ITSM version  8.2 or later.

## Accessing DEX incident diagnostics and suggested resolutions {#dex-diagnostics-guided-resolutions__section_bwc_jds_khc}

You can access incident diagnostics and suggested resolutions for DEX monitored devices from the Investigation tab of an incident record page. Navigate to the Service Operations Workspace and open the incident record from the Incidents list. For more information, see [Incident Management in Service Operations Workspace](https://servicenow-prod.fluidtopics.net/FpACAGPuU1Y9Fos6dnQ9bg "You can create and manage your incidents in Service Operations Workspace.") and [Features of the Investigation tab](https://servicenow-prod.fluidtopics.net/gyB5gBeg0YpnxHXFVC_fng "The Investigation tab displays CI metrics information along with various options. Use the options and the metrics information to view the data that helps to resolve the CI-related issues.").  
Important:  
The configuration item (CI) associated with the incident record must be a DEX monitored device.
Figure 1. DEX incident diagnostics and suggested resolutions

## Device health and metric checklist {#dex-diagnostics-guided-resolutions__section_l4h_lds_khc}

Review the overall health and performance of the device associated with the incident record in the Device health section. The Device health checklist shows details of device and application metrics for a specified duration. For
more information, see [Review device health metrics during incident investigation with DEX](https://servicenow-prod.fluidtopics.net/AtBmiO~lqLM5wFVVni8S7g "View the overall health and related metrics for Digital End-User Experience (DEX) monitored devices as part of incident investigation with DEX.").

Selecting the Refresh icon ![]()
displays the latest available data for device and application metrics.

## Top processes by CPU and memory usage {#dex-diagnostics-guided-resolutions__section_qw5_klx_h3c}

Monitor the top processes by CPU and memory usage on DEX monitored devices. Automated snapshots capture data across different time range options and display the top processes by CPU and memory usage on a device, including the
combined average usage percentages. For more information about viewing and interpreting snapshot data, see [Reviewing top processes by resource usage for DEX incident investigation](https://servicenow-prod.fluidtopics.net/CyYHnWGc5obGY3YbX_mpOw "Reviewing the top processes by CPU and memory usage on Digital End-User Experience (DEX) monitored devices helps you identify processes causing device issues.").

## Work notes for configuration item updates {#dex-diagnostics-guided-resolutions__section_ci_update_worknote_intro}

When the CI, Business Service, or Service Offering on an incident record is set or updated to an item monitored by DEX, an automatic work note is posted. For more information, see [Work notes for incident field updates with DEX](https://servicenow-prod.fluidtopics.net/J50aq2MjVIIkRfw3_w~RTw "When a configuration item (CI), Business Service, or Service Offering on an incident record is set to an item monitored by DEX, a work note is added automatically. Service desk agents use these notes to view monitoring context on the incident record.").

## Suggested resolutions and remedial actions {#dex-diagnostics-guided-resolutions__section_gvz_nds_khc}

View issue diagnosis and suggested resolutions to improve device and application performance in the Suggested resolutions tab. For more information, see [Suggested resolutions in incident investigation with DEX](https://servicenow-prod.fluidtopics.net/gv9whiTF59Eg17tNJo90ng "Review and execute suggested resolutions from the Investigation tab of incident records to resolve detected issues on DEX monitored devices.").

In addition to the suggested resolutions, you can run remedial actions from the Action library to resolve device and application issues. For more information, see [Run remedial actions from the Action library](https://servicenow-prod.fluidtopics.net/085vvDR8MdjMJQRJkvFGTg "Run remedial actions from the Action library in incident investigation with DEX to resolve detected device and application issues.").

## Playbook Experience for remedial actions {#dex-diagnostics-guided-resolutions__section_qvl_55y_khc}

Use the Playbook Experience in incident investigation with DEX to view details of remedial actions in progress, cancel ongoing actions, and view playbook history. For more information, see [Manage remedial actions in DEX incident investigation Playbook](https://servicenow-prod.fluidtopics.net/hnlGuJp3bIgOxJfCGmKujw "View current and past remedial actions executed from different sources in the Playbooks panel. Monitor or cancel actions run from the Suggested resolutions or Action library within a DEX incident investigation page.").

