Auditing malware scans in the xAgent log

Prev Next

Use the xAgent log to audit on-access and on-demand malware scans on your host endpoints. The agent log includes the following information for each malware scan performed on your host endpoint:

  • Malware scan start time

  • Scan completion status

  • Cause for incomplete malware scans (Example: a reboot an error caused an incomplete scan.)

  • Malware scan duration

  • Number of files scanned

  • Number of detections identified

  • Malware scan type (full, quick, or active memory)

This section describes how to extract the log from the xAgent on your host endpoint.

To extract the agent log:

C:<installdir>xagt.exe -g <LogFileName>

The example below extracts the agent log file (log.ext) from the \Program Files (x86)\fireeye\ directory.

\Program Files (x86)\fireeye\xagt\xagt.exe -g log.txt

  1. Using administrator access, open command line prompt on a host endpoint currently running Trellix Endpoint Security (HX) xAgent version 28.

  2. Enter the following command to extract the agent log: