Configure the Common policy settings to define the log settings.
For details about product features, usage, and best practices, click ? or Help.
Log on to the ePO - On-prem server as an administrator.
From the Policy Catalog, select Endpoint Security Common as the product, then Options as the category.
Click New Policy, type a name for the policy, then click OK.
On the Policy Catalog page, click Show Advanced, then define these options:
In this section...
In this category...
Configure...
Client Interface Mode
Full access — Allows the managed system user to view or change all feature settings using the local system password credentials.
Uninstallation
Require password to uninstall the client — Enables the password authentication during uninstallation.
Password —Specifies the password to be authenticated during uninstallation.
Confirm Password — Confirms the password to be authenticated during uninstallation.
Client logging
Activity Logging
Activity logging
Enable activity logging — Enables logging of all Trellix Endpoint Security (ENS) for Linux activity.
Limit size (MB) of each of the activity log files — Limits the log file size between 1 MB and 999 MB. The default is 10 MB. When the file size exceeds the limit, the current file is backed up and a new log file is created. The software retains the last 5 versions of the log files.
Debug Logging
Enable for Threat Prevention — Enables debug logging for Threat Prevention. You can find the logs at the default destionation:
/var/McAfee/ens/log/tp/or your configured custom log path.
Event Logging
Enable for Threat Prevention — Enables debug logging for Threat Prevention. You can find the logs at:
/var/McAfee/ens/log/tp/or your configured custom log path.
Send events to Trellix ePO - On-prem — Sends all events logged to the Event Log on the client to ePO - On-prem.
Log events to Windows Event Log or syslog — Sends all events to the Trellix Endpoint Security (ENS) for Linux client syslog. The location of syslog is configurable on Linux systems.
Proxy Settings
No proxy server — Threat Prevention directly sends the request to the Trellix GTI server. For managed systems, this is the default option selected in the ePO - On-prem Common Policy settings. For standalone systems, the software always works in this mode.
Use system proxy settings — Threat Prevention uses the proxy server settings configured in the managed Linux system. You must configure the managed Linux system with the proxy server settings, then enforce the policy from ePO - On-prem. Use the Enable HTTP proxy authentication option when the credentials of the proxy server are not defined in the managed Linux systems.
Configure proxy server — Threat Prevention uses the proxy server settings such as IP address and credentials in the Common Policy.
HTTP address (must be DNS, IPv4, or IPv6) — Specifies the IP address of the proxy server. For IPv6, you must specify the IP address in square bracket. For example,
http://[xxxx:xxxx:xxxx:x::xx]:<port-number>.Port — Specifies the port number. The default port number is 3128.
Exclude these addresses — Excludes the addresses specified in this list.
Enable proxy authentications — Enables proxy authentications for your managed Linux systems.
User name — Specifies the user.
Password — Specifies the password.
Confirm Password — Confirms the password.
Click Save.
In the System Tree, select the systems or groups.
In the right pane, click the Group Details tab, then click Wake Up Agents.
In Force policy update, select Force complete policy and task update, then click OK.