---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Event monitoring with DEX

# Event monitoring with DEX {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
DEX collects and analyzes system events from managed devices so that you can detect issues, set alert thresholds, and investigate incidents faster. You can monitor system-level events
across endpoints and take action before issues impact employees.

Event monitoring extends Digital End-User Experience (DEX) capabilities beyond performance metrics to include system event tracking. This feature enables you to monitor critical system events on managed Windows and macOS devices, providing deeper visibility into device health and enabling faster incident investigation.

System events are discrete, timestamped occurrences that the OS records when something happens on a device---for example, an application crash, a service failure, or a security-related action. Unlike
performance metrics, which capture continuous measurements such as CPU utilization, events are point-in-time records that can indicate the root cause of a broader issue.

Event monitoring uses a lightweight agent-based collection process that minimizes impact on device performance while capturing critical system events.

You can configure up to 25 events for each OS type.

## Supported event types {#event-monitoring-dex__section_fq2_xjz_q3c}

DEX supports event monitoring on both Windows and macOS. On Windows, events are identified by a numeric Event ID from the Windows Event Log. On macOS, you define events using a regular expression that matches the system log entry of interest. For each platform, you specify the event name, Event ID or regular expression, a description, and the target operating
system.

You can configure up to 25 events for each operating system type. See [Add an event to monitor](https://servicenow-prod.fluidtopics.net/NUpfHzK0X4Cc6eRq_aaDFA "Add a custom event to extend monitoring beyond the base events using the Event Log Monitoring Config table.") to create a custom event rule.

DEX also installs a set of base system event
log monitoring configurations that are active by default and count toward this limit. For
the full list, see [Event log monitoring configurations installed with DEX](https://servicenow-prod.fluidtopics.net/emcRstQMRFvTdm2CvK7UgQ "The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations that are active by default. Use this reference to identify the monitored events, log sources, and matching criteria for Windows and macOS devices.").

