The activity, error, and debug log files record events that occur on systems with Trellix ENS enabled.
All activity and debug log files are stored in the following default location:
%ProgramData%\McAfee\Endpoint Security\Logs
Each module, feature, or technology places activity or debug logging in a separate file. All modules place error logging in one file, EndpointSecurityPlatform_Errors.log.
Enabling debug logging for any module also enables debug logging for the Common module features, such as Self Protection.
Module | Feature or technology | File name |
|---|---|---|
Adaptive Threat Protection | AdvancedThreatProtection_Activity.log | |
AdvancedThreatProtection_Debug.log | ||
Dynamic Application Containment | DynamicApplicationContainment_Activity.log | |
DynamicApplicationContainment_Debug.log | ||
False positive mitigation | FalsePositiveMitigation_Activity.log | |
FalsePositiveMitigation_Debug.log | ||
Enhanced Remediation | EnhancedRemediation_Debug.log | |
Common | Errors | EndpointSecurityPlatform_Errors.log Contains error logs for all modules. |
Tip
Best practice For information on Trellix ENS event messages, see KB85494.
By default, installation log files are stored here:
TEMP\McAfeeLogs, which is the Windows system TEMP folder. (Managed systems)
%TEMP%\McAfeeLogs, which is the Windows user TEMP folder. (Self-managed systems)