Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

New DEX event form

The New record form for DEX event monitoring enables you to add events to monitor.

FieldDescription
NameAssigns the event a name, for example "Application crash."
OS TypeSelects the operating system for which the event is configured:- Windows - macOS
Query TypeSelects a message pattern used to identify the event in the log: - Contains \(Substring\) is used for plain-text matching. - Regex \(Pattern Matching\) is used for regular expression matching.
ActiveSelects to activate or deselects to make the event inactive.
ApplicationDefaults to Application and Device Health, which owns the record.
Event messageIdentifies the message for which the event rule searches to trigger an alert.This field is optional on Windows devices, and required on macOS devices.
DomainDefaults to global.The record is visible across all domains.
Log levelSelects the severity level of the log event being monitored, such as Debug, Error, Fault, Info, or Warning.
macOS CategorySelects the logging category associated with the event, used to narrow down log sources.This field only appears for the events on macOS devices. This filed is optional. Adding a category could improve the performance and accuracy.
macOS ProcessSelects a specific process that generates the event \(for example, kernel or loginwindow\).This field only appears for the events on macOS devices. This field is optional. Adding a category could improve the performance and accuracy.
macOS SubsystemSelects a subsystem identifier \(typically in reverse-domain notation, such as com.apple.Authorization\) used to filter logs.This field only appears for the events on macOS devices. This filed is optional.
Windows Event ID\(s\)Assigns a numeric ID used to identify the event in the Windows Event Log.This field only appears for the events on Windows devices. This filed is required.
Windows Log SourceIdentifies the source where the event is recorded, such as Application, System, or Security.This field only appears for the events on Windows devices. This filed is required.

Parent Topic:DEX Application and Device Health reference