---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Event configurations installed with DEX

# Event log monitoring configurations installed with DEX {#ariaid-title1}

Release version: Australia  
Updated July 28, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations that are active by default. Use this reference to identify the monitored events, log sources, and matching criteria
for Windows and macOS devices.
The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations in the Event Log Monitoring Configs table. All 20 configurations are active by default: 11 for Windows and 9 for macOS.  
Note:  
These base system configurations count toward the 25-event maximum per operating system. On Windows, the 11 base system configurations leave 14 available for custom events. On macOS, the 9 base system configurations leave 16 available. To add a custom event, remove any base system configuration you don't need. See [Add an event to monitor](https://servicenow-prod.fluidtopics.net/NUpfHzK0X4Cc6eRq_aaDFA "Add a custom event to extend monitoring beyond the base events using the Event Log Monitoring Config table."). For field descriptions, see [New DEX event form](https://servicenow-prod.fluidtopics.net/1nayxMeZg7RX~NfIdAyf6g "The New record form for DEX event monitoring enables you to add events to monitor.").  
{#event-log-monitoring-configs-installed-with-dex__table_oob_event_configs_windows__entry__3}

| Configuration name | Event ID | Log source |
|-|-|-|
| Resource exhaustion / low memory | 2004 | System |
| Windows Update installation failure | 20 | Setup |
| Wi-Fi -- WLAN connection failed | 8001 | System |
| VPN connection failure | 20227 | System |
| Application crashes | 1000 | Application |
| Windows Defender threat detected | 1116 | Microsoft-Windows-Windows Defender/Operational |
| Device driver load failure | 219 | System |
| Failed login attempt | 4625 | Security |
| Unexpected system shutdown | 41 | System |
| USB device connected | 2003 | System |
| MSI installer failure | 1024 | Application |
[Table 1. Windows event log monitoring configurations]

{#event-log-monitoring-configs-installed-with-dex__table_oob_event_configs_windows}  
{#event-log-monitoring-configs-installed-with-dex__table_oob_event_configs_macos__entry__5}

| Configuration name | Process | Subsystem or category | Query type | Event message |
|-|-|-|-|-|
| VPN disconnected | locationd | com.apple.networkextension | Contains | NEVPNConnectivityStateDisconnecting |
| Software installation failed | installer | --- | Regex | .\*(Installation\|Package\|cancelled).\* |
| Software update failed | softwareupdated | --- | Regex | .\*(failed\|error\|unable\|download\|install).\* |
| USB storage mounted | --- | com.apple.DiskArbitration | Contains | mounted |
| Login failed | authorizationhost | com.apple.Authorization | Contains | pam_authenticate failed |
| Wi-Fi disconnected | wifip2pd | com.apple.wifip2pd | Contains | not associated |
| USB device connected | kernel | --- | Contains | enumerated |
| Kernel panics | kernel | com.apple.system.logging.kernel_panics | Contains | panic |
| Application crash | loginwindow | com.apple.loginwindow.logging | Contains | crashed |
[Table 2. macOS event log monitoring configurations]

{#event-log-monitoring-configs-installed-with-dex__table_oob_event_configs_macos}

