Event log monitoring configurations installed with DEX

  • Release version: Australia
  • Updated July 28, 2026
  • 1 minute to read
  • The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations that are active by default. Use this reference to identify the monitored events, log sources, and matching criteria for Windows and macOS devices.

    The Application and Device Health plugin (com.sn_dex) installs 20 event log monitoring configurations in the Event Log Monitoring Configs table. All 20 configurations are active by default: 11 for Windows and 9 for macOS.

    Note:
    These base system configurations count toward the 25-event maximum per operating system. On Windows, the 11 base system configurations leave 14 available for custom events. On macOS, the 9 base system configurations leave 16 available. To add a custom event, remove any base system configuration you don't need. See Add an event to monitor. For field descriptions, see New DEX event form.
    Table 1. Windows event log monitoring configurations
    Configuration name Event ID Log source
    Resource exhaustion / low memory 2004 System
    Windows Update installation failure 20 Setup
    Wi-Fi – WLAN connection failed 8001 System
    VPN connection failure 20227 System
    Application crashes 1000 Application
    Windows Defender threat detected 1116 Microsoft-Windows-Windows Defender/Operational
    Device driver load failure 219 System
    Failed login attempt 4625 Security
    Unexpected system shutdown 41 System
    USB device connected 2003 System
    MSI installer failure 1024 Application
    Table 2. macOS event log monitoring configurations
    Configuration name Process Subsystem or category Query type Event message
    VPN disconnected locationd com.apple.networkextension Contains NEVPNConnectivityStateDisconnecting
    Software installation failed installer Regex .*(Installation|Package|cancelled).*
    Software update failed softwareupdated Regex .*(failed|error|unable|download|install).*
    USB storage mounted com.apple.DiskArbitration Contains mounted
    Login failed authorizationhost com.apple.Authorization Contains pam_authenticate failed
    Wi-Fi disconnected wifip2pd com.apple.wifip2pd Contains not associated
    USB device connected kernel Contains enumerated
    Kernel panics kernel com.apple.system.logging.kernel_panics Contains panic
    Application crash loginwindow com.apple.loginwindow.logging Contains crashed