The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Accessing the log files

Prev Next

To troubleshoot installation problems, see the directories and access the log files.

Endpoint Security Threat Intelligence server/var/Trellix/tieserver/logs/tieserver.log

Endpoint Security Threat Intelligence module \ProgramData\McAfee\EndpointSecurity\Logs\ThreatIntelligence_Activity.log

TIE server

  • /var/Trellix/tieserver/logs/tieserver.log

  • /var/Trellix/tieserver/logs/tieserver-start.log

  • /var/Trellix/tieserver/logs/tieserver-lib.log

  • /tmp/reconfig-tie.log (for operation mode transitions)

Endpoint Security Threat Intelligence%programdata%\McAfee\Endpoint Security\Logs\ThreatIntelligence_Activity and ThreatIntelligence_Debug

Trellix DXL Client%programdata%\McAfee\Data_eXchange_Layer

Trellix DXL Broker/var/McAfee/dxlbroker/logs/dxlbroker.log

Trellix Agent/var/log/MFEcma-[MA_VERSION]-[MA_BUILD].log

See KB82850 for details about using the Minimum Escalation Requirements (MER) tool to collect product data from the server and contact Technical Support. This tool runs in the server appliance.

See KB59385 for details about using the MER tool with other Trellix products.