In Windows environments, the logs for upgrade jobs are stored in log files in the /ProgramData/FireEye/xagt/upgrade/ directory. The logs are only available when upgrades are done using the Endpoint Security server.
In macOS environments, log data for upgrade jobs is stored in the installer.log file in the /var/log/ directory.
In Linux environments, log data for upgrade jobs is stored in the /var/lib/fireeye/xagt/upgrade directory.