You can enable and disable the xAgent logging policy for all host sets using the xAgent default policy. You can also enable and disable the xAgent logging policy for selected host sets using a custom policy.
This section covers the following topics:
Note
The xAgent Component Logging features permit you to enable enhanced logging on your HX appliance. You should only enable these features when instructed by the Trellix support team.
Enabling the xAgent logging policy
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Agent Logging tab.
.jpg)
Toggle the Agent Logging ON/OFF switch to ON.
Click the Agent log level menu and select the agent log level. See Understanding Agent Logging Levels for more information.
Enter the size of the log database in the Log Storage box.
Default value: 50,000 events
Minimum:10,000 events
Maximum: 5,000,000 events
From the Component Logging section, click the checkbox next to the each component to enable agent logging.
Click Save.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Agent Logging tab to access the Edit Policies page.
.jpg)
Toggle the Agent Logging ON/OFF switch to ON.
Click the Agent log level menu and select the agent log level. See Understanding Agent Logging Levels for more information.
Enter the size of the log database in the Log Storage box.
From the Component Logging section, click the checkbox next to each component to enable agent logging.
Click Save.
Disabling the xAgent logging policy
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Agent Logging tab.
.jpg)
Toggle the Agent Logging ON/OFF switch to OFF.
Click Save.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
In the Policies table, click the link for the custom policy you want to modify.
Select the Agent Logging tab to access the Edit Policies page.
.jpg)
Toggle the Agent Logging ON/OFF switch to OFF.
Click Save.