Event log monitoring configurations installed with DEX
The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations that are active by default. Use this reference to identify the monitored events, log sources, and matching criteria for Windows and macOS devices.
The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations in the Event Log Monitoring Configs table. All 20 configurations are active by default: 11 for Windows and 9 for macOS.
Note:
These base system configurations count toward the 25-event maximum per operating system. On Windows, the 11 base system configurations leave 14 available for custom events. On macOS, the 9 base system configurations leave 16 available. To add a custom event, remove any base system configuration you don't need. See Add an event to monitor. For field descriptions, see New DEX event form.
| Configuration name | Event ID | Log source |
|---|---|---|
| Resource exhaustion / low memory | 2004 | System |
| Windows Update installation failure | 20 | Setup |
| Wi-Fi – WLAN connection failed | 8001 | System |
| VPN connection failure | 20227 | System |
| Application crashes | 1000 | Application |
| Windows Defender threat detected | 1116 | Microsoft-Windows-Windows Defender/Operational |
| Device driver load failure | 219 | System |
| Failed login attempt | 4625 | Security |
| Unexpected system shutdown | 41 | System |
| USB device connected | 2003 | System |
| MSI installer failure | 1024 | Application |
| Configuration name | Process | Subsystem or category | Query type | Event message |
|---|---|---|---|---|
| VPN disconnected | locationd | com.apple.networkextension | Contains | NEVPNConnectivityStateDisconnecting |
| Software installation failed | installer | — | Regex | .*(Installation|Package|cancelled).* |
| Software update failed | softwareupdated | — | Regex | .*(failed|error|unable|download|install).* |
| USB storage mounted | — | com.apple.DiskArbitration | Contains | mounted |
| Login failed | authorizationhost | com.apple.Authorization | Contains | pam_authenticate failed |
| Wi-Fi disconnected | wifip2pd | com.apple.wifip2pd | Contains | not associated |
| USB device connected | kernel | — | Contains | enumerated |
| Kernel panics | kernel | com.apple.system.logging.kernel_panics | Contains | panic |
| Application crash | loginwindow | com.apple.loginwindow.logging | Contains | crashed |