---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Incident diagnostics and suggested resolutions

# Incident investigation with DEX {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Incident investigation with DEX

ServiceNow enables service desk agents to diagnose and resolve issues on Digital End-User Experience (DEX) monitored devices directly from incident records using DEX diagnostics and suggested resolutions.
This capability offers a comprehensive view of device and application health, assisting in identifying and resolving common issues faster, thereby improving incident resolution times and enhancing the service desk experience.
Show full answer Show less  
**Note:** This feature is available starting from the Zurich release and requires Service Operations Workspace for ITSM version 8.2 or later.

## Accessing DEX Incident Diagnostics

Agents can access DEX incident diagnostics and suggested resolutions via the Investigation tab on an incident record within the Service Operations Workspace. The incident must be linked to a configuration item (CI) that is a DEX monitored device to enable this functionality.

## Key Features

* **Device Health and Metric Checklist:** Provides an overview of device and application performance metrics over a specified period, with the ability to refresh data for the latest insights.
* **Top Processes by CPU and Memory Usage:** Displays automated snapshots of processes consuming the most CPU and memory on the device, helping to pinpoint resource-intensive activities.
* **Work Notes for Configuration Item Updates:** Automatically logs work notes when the CI, Business Service, or Service Offering on an incident record is updated to a DEX monitored item, ensuring traceability.
* **Suggested Resolutions and Remedial Actions:** Offers issue diagnoses and solutions to improve device and application performance, with the option to execute remedial actions directly from an Action library.
* **Playbook Experience for Remedial Actions:** Allows agents to monitor ongoing remedial actions, cancel them if necessary, and review playbook execution history for better incident management.

## Benefits for ServiceNow Customers

By integrating DEX diagnostics into incident investigation, ServiceNow customers can expect faster and more accurate troubleshooting of end-user device issues. This integration streamlines the incident resolution process by providing actionable insights and automated remediation options, leading to improved end-user satisfaction and more efficient service desk operations.  
Service desk agents can diagnose and resolve issues for Digital End-User Experience (DEX) monitored devices from an incident record by using DEX diagnostics and suggested resolutions.  
Incident investigation with DEX provides a comprehensive view of device and application health metrics, issue diagnosis, and suggested resolutions. It helps identify and resolve common device and application issues, leading to faster incident resolution and enhanced service desk experience.  
Important:  
Incident investigation with DEX is available from the Zurich release and requires Service Operations Workspace for ITSM version  8.2 or later.

## Accessing DEX incident diagnostics and suggested resolutions {#dex-diagnostics-guided-resolutions__section_bwc_jds_khc}

You can access incident diagnostics and suggested resolutions for DEX monitored devices from the Investigation tab of an incident record page. Navigate to the Service Operations Workspace and open the incident record from the Incidents list. For more information, see [Incident Management in Service Operations Workspace](https://www.servicenow.com/docs/FpACAGPuU1Y9Fos6dnQ9bg "You can create and manage your incidents in Service Operations Workspace.") and [Features of the Investigation tab](https://www.servicenow.com/docs/gyB5gBeg0YpnxHXFVC_fng "The Investigation tab displays CI metrics information along with various options. Use the options and the metrics information to view the data that helps to resolve the CI-related issues.").  
Important:  
The configuration item (CI) associated with the incident record must be a DEX monitored device.
Figure 1. DEX incident diagnostics and suggested resolutions

## Device health and metric checklist {#dex-diagnostics-guided-resolutions__section_l4h_lds_khc}

Review the overall health and performance of the device associated with the incident record in the Device health section. The Device health checklist shows details of device and application metrics for a specified duration. For
more information, see [Review device health metrics during incident investigation with DEX](https://www.servicenow.com/docs/AtBmiO~lqLM5wFVVni8S7g "View the overall health and related metrics for Digital End-User Experience (DEX) monitored devices as part of incident investigation with DEX.").

Selecting the Refresh icon ![]()
displays the latest available data for device and application metrics.

## Top processes by CPU and memory usage {#dex-diagnostics-guided-resolutions__section_qw5_klx_h3c}

Monitor the top processes by CPU and memory usage on DEX monitored devices. Automated snapshots capture data across different time range options and display the top processes by CPU and memory usage on a device, including the
combined average usage percentages. For more information about viewing and interpreting snapshot data, see [Reviewing top processes by resource usage for DEX incident investigation](https://www.servicenow.com/docs/CyYHnWGc5obGY3YbX_mpOw "Reviewing the top processes by CPU and memory usage on Digital End-User Experience (DEX) monitored devices helps you identify processes causing device issues.").

## Work notes for configuration item updates {#dex-diagnostics-guided-resolutions__section_ci_update_worknote_intro}

When the CI, Business Service, or Service Offering on an incident record is set or updated to an item monitored by DEX, an automatic work note is posted. For more information, see [Work notes for incident field updates with DEX](https://www.servicenow.com/docs/J50aq2MjVIIkRfw3_w~RTw "When a configuration item (CI), Business Service, or Service Offering on an incident record is set to an item monitored by DEX, a work note is added automatically. Service desk agents use these notes to view monitoring context on the incident record.").

## Suggested resolutions and remedial actions {#dex-diagnostics-guided-resolutions__section_gvz_nds_khc}

View issue diagnosis and suggested resolutions to improve device and application performance in the Suggested resolutions tab. For more information, see [Suggested resolutions in incident investigation with DEX](https://www.servicenow.com/docs/gv9whiTF59Eg17tNJo90ng "Review and execute suggested resolutions from the Investigation tab of incident records to resolve detected issues on DEX monitored devices.").

In addition to the suggested resolutions, you can run remedial actions from the Action library to resolve device and application issues. For more information, see [Run remedial actions from the Action library](https://www.servicenow.com/docs/085vvDR8MdjMJQRJkvFGTg "Run remedial actions from the Action library in incident investigation with DEX to resolve detected device and application issues.").

## Playbook Experience for remedial actions {#dex-diagnostics-guided-resolutions__section_qvl_55y_khc}

Use the Playbook Experience in incident investigation with DEX to view details of remedial actions in progress, cancel ongoing actions, and view playbook history. For more information, see [Manage remedial actions in DEX incident investigation Playbook](https://www.servicenow.com/docs/hnlGuJp3bIgOxJfCGmKujw "View current and past remedial actions executed from different sources in the Playbooks panel. Monitor or cancel actions run from the Suggested resolutions or Action library within a DEX incident investigation page.").

