---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Metrics monitored by DEX on macOS

# Metrics monitored by DEX on macOS {#ariaid-title1}

Release version: Australia  
Updated June 26, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read  
Review the endpoint performance and compliance metrics that DEX collects from managed macOS devices, including collection intervals, and associated check definitions and policies.

## Application metrics {#metrics-monitored-by-dex-macos__section_mac_metrics}

{#metrics-monitored-by-dex-macos__table_mac_metrics__entry__8}

| Metric Name | Key | Description | Sub-metrics / Output fields | Unit | Policy: Interval (min) | Check Definition Name | Required Privileges |
|-|-|-|-|-|-|-|-|
| Application version | appVersion | Version string of the installed Mac application. Snapshot metric retrieved via the osquery `apps` table. | Single metric --- `appVersion` (string) | N/A | 1,440 | os.mac.check-app-version | Sudo permissions |
| CPU usage | cpu_usage | Percentage of CPU consumed by the target application's processes. Point-in-time gauge sampled every 5 minutes; rounded to 2 decimal places. | Single metric --- `cpu_usage` (percentage, gauge) | % | 5 | os.mac.check-app-cpu-usage | No elevated privileges required |
| Crashes | crashes | Count of application crashes and crash event details. Source: osquery `crash_log` table. | `crashes` (count); `crash_details` (array): timestamp, process_name, responsible, exception_type, signal | count | 5 | os.mac.check-app-crashes | Sudo permissions |
| Freezes | freezes | Count of application freeze or hang events on the device. | Single metric --- `freezes` (count) per application. | count | 5 | os.mac.check-app-freezes | Sudo permissions |
| IO usage (read) | io_usage_read | Bytes read per second from disk by application processes. | Single metric --- `io_usage_read` (bytes/second, gauge) | Bps | 5 | os.mac.check-app-io-usage-read | Sudo permissions |
| IO usage (write) | io_usage_write | Bytes written per second to disk by application processes. | Single metric --- `io_usage_write` (bytes/second, gauge) | Bps | 5 | os.mac.check-app-io-usage-write | Sudo permissions |
| Is installed | is_installed | Boolean indicating whether the target application is installed on the device. Prerequisite for all other application metrics. | Single metric --- `is_installed` (boolean) | Boolean | N/A | os.mac.check-app-is-installed | Sudo permissions |
| Is running | is_running | Boolean indicating whether at least one process of the target application is currently running. | Single metric --- `is_running` (boolean, gauge) | Boolean | 5 | os.mac.check-app-is-running | Sudo permissions |
| Last access time | last_access_time | Unix timestamp (milliseconds) of the last time the application was observed running. Daily snapshot. Sudo permissions are required. Note: Data is available only for the past 7 days due to macOS log retention limits. | Single metric --- `last_access_time` (milliseconds since epoch) | milliseconds | 5 | os.mac.check-app-last-access-time | Sudo permissions |
| Last updated | last_updated | Timestamp of the most recent application update installation. Derived from the `mdls` command which reads file system extended attributes of the .app bundle. Sudo permissions are required. | Single metric --- `last_updated` (Unix timestamp) | seconds | N/A | os.mac.check-app-last-updated | Sudo permissions |
| Listening ports | listening_ports | List of TCP and UDP port numbers on which the application is actively listening. Latest snapshot only; not stored historically. | Single metric --- `listening_ports` (array of integer port numbers) | N/A | N/A | os.mac.check-app-listening-ports | Sudo permissions |
| RAM usage | memory_usage | Percentage of physical RAM consumed by the target application's processes relative to total system RAM. | Single metric --- `memory_usage` (percentage, gauge) | % | 5 | os.mac.check-app-memory-usage | No elevated privileges required |
| Uptime | uptime | Continuous running time of each application process in milliseconds since its last start. Derived from the `ps` command elapsed time. | Single metric --- `uptime` (milliseconds, gauge) | milliseconds | 5 | os.mac.check-app-uptime | No elevated privileges required |
[ ]

{#metrics-monitored-by-dex-macos__table_mac_metrics}

## Device metrics {#metrics-monitored-by-dex-macos__section_ybt_vd1_5jc}

{#metrics-monitored-by-dex-macos__table_uc4_2bj_sjc__entry__8}

| Metric Name | Key | Description | Sub-metrics / Output fields | Unit | Policy: Interval (min) | Check Definition Name | Required privileges |
|-|-|-|-|-|-|-|-|
| Admin users | admin_users | List of local macOS user accounts with administrator (admin group) privileges. Snapshot only. | `admin_users` (array): `username` (string), `uid` (integer) | N/A | N/A | os.mac.check-system-admin-users | No elevated privileges required |
| Battery charge percentage | battery_charge_percentage | Current macOS battery charge percentage from osquery `battery` table. Integer value 0-100. | Single metric --- `battery_charge_percentage` (integer %, gauge) with `battery_id` attribute | % | 5 | os.mac.check-system-battery-charge-percentage | No elevated privileges required |
| Battery details | battery_details | Comprehensive macOS battery health snapshot from osquery `battery` table. Includes charge percentage, health, condition, cycle count, design and full-charge capacity (converted from mAh to mWh using design voltage), maximum capacity percentage, and installed battery count. | `charge_percentage` (%); `health` (Good/Moderate/Poor); `condition`; `cycle_count`; `designed_capacity` (mWh); `full_charge_capacity` (mWh); `maximum_capacity` (%); `design_voltage` (volts); `installed_batteries` (count) | N/A | 1,440 | os.mac.check-system-battery-details | No elevated privileges required |
| CPU details | cpu_details | macOS CPU hardware details including model name, physical processor count, logical processor count, and architecture. Daily snapshot. | `model`; `number_of_cores`; `number_of_logical_processors`; `architecture` (e.g., arm64 or x86_64) | N/A | 1,440 | os.mac.check-system-cpu-details | No elevated privileges required |
| CPU usage | cpu_usage | Aggregate CPU utilization percentage across all CPU cores on macOS. Computed as 100 minus the average idle percentage across all cores, parsed from the `top` command output. | Single metric --- `cpu_usage` (percentage, gauge) | % | 5 | os.mac.check-system-cpu-usage | No elevated privileges required |
| Device crashes | crashes | Count of device-level crashes (kernel panics, system crashes) on macOS within the 5-minute collection window. | Single metric --- `crashes` (count per 5-min window, gauge) | count | 5 | os.mac.check-system-crashes | No elevated privileges required |
| Device details | device_details | macOS hardware identity snapshot: model name, serial number, and device type via `system_profiler SPHardwareDataType`. | `model` (e.g., MacBook Pro 14-inch); `serial_number`; `device_type` | N/A | 1,440 | os.mac.check-system-device-details | No elevated privileges required |
| Device events | device_events | macOS device events during a specified time interval. Captures six event types: last_boot, logged_in_users, softwares_installed, softwares_updated, users_added, and passwords_reset. Sudo permissions are required. | `last_boot` (timestamp); `logged_in_users` (array); `softwares_installed` (array); `softwares_updated` (array); `users_added` (array); `passwords_reset` (array) | N/A | 1,440 | os.mac.check-system-device-events | Sudo permissions |
| Disk details | disk_details | Per-disk snapshot of total space, free space, and used space in bytes for the primary macOS disk. Data from the osquery mounts table (path = '/'). | `total_space` (bytes); `free_space` (bytes); `used_space` (bytes) | N/A | 1,440 | os.mac.check-system-disk-details | No elevated privileges required |
| Disk IO usage (read) | io_usage_read | Device-wide disk read throughput in bytes per second on macOS. Two-sample delta from osquery `processes` table `disk_bytes_read`. | Single metric --- `io_usage_read` (bytes/second, gauge) | Bps | 5 | os.mac.check-system-disk-io-usage-read | Sudo permissions |
| Disk IO usage (write) | io_usage_write | Device-wide disk write throughput in bytes per second on macOS. | Single metric --- `io_usage_write` (bytes/second, gauge) | Bps | 5 | os.mac.check-system-disk-io-usage-write | Sudo permissions |
| Disk usage\* | disk_usage | Percentage of primary disk space used on macOS, computed as `(total - free) / total * 100`. | Single metric --- `disk_usage` (percentage, gauge) | % | 5 | os.mac.check-system-disk-usage | No elevated privileges required |
| Energy consumption | energy_consumption | Energy consumed by the macOS device over the next 5-minute window in milliwatt-hours. Measured via the macOS `powermetrics` tool. | Single metric --- `energy_consumption` (milliwatt-hour, gauge) with `battery_id` attribute | mWh | 5 | os.mac.check-system-energy-consumption | Sudo permissions |
| Firewall enabled | firewall_enabled | Boolean status of the macOS application-layer firewall (Application Firewall / `socketfilterfw`). | Single metric --- `firewall_enabled` (boolean) | N/A | 1,440 | os.mac.check-system-firewall-enabled | No elevated privileges required |
| Incoming network bytes | incoming_bytes | Total incoming network bytes per second aggregated across all network interfaces on macOS. Two-sample delta calculation from osquery `interface_details` table. | Single metric --- `incoming_bytes` (bytes/second, gauge) | Bps | N/A | os.mac.check-system-net-bytes-incoming | No elevated privileges required |
| Last access time | last_access_time | Unix timestamp (milliseconds) of the last time the macOS device was physically accessed by a user, based on display activity. Note: Works with the display on or off. | Single metric --- `last_access_time` (milliseconds since epoch) | milliseconds | 1,440 | os.mac.check-system-last-access-time | No elevated privileges required |
| Logged-in users | logged_in | List of users currently logged into the macOS including username and uid. | `logged_in` (array): `user` (string); `uid` (integer) | N/A | 1,440 | os.mac.check-system-logged-in-users | No elevated privileges required |
| Network connectivity details | network_details | Full network interface snapshot for both Wi-Fi and Ethernet on macOS. | Wi-Fi: `name`; `ssid`; `bssid`; `channel`; `rssi` (dBm); `transmit_rate` (Mbps); `mac_address`; `state` Ethernet: `name`; `mac_address`; `link_speed`; `media`; `status` | N/A | 1,440 | os.mac.check-system-network-details | No elevated privileges required |
| OS details | os_details | macOS inventory snapshot: OS name (for example, macOS Ventura), version, platform (darwin), architecture, and install date. | `name`; `version`; `platform`; `architecture`; `install_date` (timestamp) | N/A | 1,440 | os.mac.check-system-os-details | No elevated privileges required |
| OS setup details | os_setup_details | Approximate age of the macOS installation, indicating how long the current OS has been set up on the device. | `os_install_date` (timestamp); `os_age_days` (integer) | N/A | 1,440 | os.mac.check-system-os-setup-details | No elevated privileges required |
| Outgoing network bytes | outgoing_bytes | Total outgoing network bytes per second across all macOS network interfaces. Two-sample delta from osquery `interface_details` `outbytes` column. | Single metric --- `outgoing_bytes` (bytes/second, gauge) | Bps | N/A | os.mac.check-system-net-bytes-outgoing | No elevated privileges required |
| Pending system updates | pending_updates | List of available pending software updates on macOS (both system and app store updates). | Per update: `update_name`; `version`; `description`; `restart_required` | N/A | 1,440 | os.mac.check-system-pending-updates | No elevated privileges required |
| Power consumption | power_consumption | Instantaneous power consumption of the macOS device in milliwatts via `powermetrics`. | Single metric --- `power_consumption` (milliwatts, gauge) | mW | 5 | os.mac.check-system-power-consumption | Sudo permissions |
| RAM usage | memory_usage | System-wide physical memory utilization percentage on macOS. Calculated from `vm_stat` output. | `memory_total` (bytes); `memory_available` (bytes); `memory_usage` (bytes); `memory_usage_percentage` (gauge) | % | 5 | os.mac.check-system-memory-usage | No elevated privileges required |
| Reboot details | reboot_details | Last reboot timestamp for the macOS device. Calculated from osquery `system_info` uptime. | `last_reboot_timestamp` (Unix timestamp in seconds) | seconds | 1,440 | os.mac.check-system-reboot-details | No elevated privileges required |
| Session details | session_details | Session duration in minutes for each currently logged-in user on the macOS. | Array of session objects: `user` (username); `session_time` (minutes since login) | minutes | 1,440 | os.mac.check-system-session-details | No elevated privileges required |
| System compliance | system_compliance_details | Compliance rating (percentage) for the macOS device based on configured compliance rules. Lists non-compliant metrics and apps. | `compliance_rating` (percentage); `non_compliant_apps` (array); `non_compliant_metrics` (array) | % | 1,440 | os.mac.check-system-compliance-details | No elevated privileges required |
| System time | time | Current macOS system time as Unix epoch seconds (UTC). Used for time-drift detection and telemetry alignment. | Single metric --- `time` (Unix epoch seconds, gauge) | seconds | N/A | os.mac.check-system-time | No elevated privileges required |
| Uptime | uptime | Time in milliseconds since the last device boot on macOS. Derived from osquery `system_info`. | Single metric --- `uptime` (milliseconds, gauge) | milliseconds | 5 | os.mac.check-system-uptime | No elevated privileges required |
| VPN details | vpn_details | VPN connection status on macOS as a boolean. Detected by comparing DNS search domains in the resolver versus macOS network settings. | `vpn_status` (boolean); `vpn_domains` (array of detected VPN search domains) | Boolean | 30 | os.mac.check-system-vpn-details | No elevated privileges required |
| Wi-Fi RSSI | wifi_rssi | Wi-Fi RSSI (Received Signal Strength Indicator) in dBm from osquery `wifi_status` table. Negative integer value (for example, -65 dBm). | Single metric --- `wifi_rssi` (dBm, negative integer, gauge) | dBm | 5 | os.mac.check-system-wifi-rssi | Sudo permissions |
| Wi-Fi transmit rate | wifi_transmit_rate | Wi-Fi transmit rate in Mbps on macOS from osquery `wifi_status` table. | Single metric --- `wifi_transmit_rate` (Mbps, gauge) | Mbps | 5 | os.mac.check-system-wifi-transmit-rate | Sudo permissions |
[ ]

{#metrics-monitored-by-dex-macos__table_uc4_2bj_sjc}  
Note:  
\* The Disk Usage metric reports storage consumption. For disk I/O throughput by process, see the Disk Usage action in [Digital End-User Experience remedial actions](https://servicenow-prod.fluidtopics.net/INx3jbb_iuk6UuenECZ7SQ "ServiceNow Digital End-User Experience (DEX) provides base system remedial actions to resolve issues on DEX monitored devices.").

