The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Log file names and locations

Prev Next

The activity, error, and debug log files record events that occur on systems with Trellix products enabled.

All activity and debug log files are stored here:

%ProgramData%\McAfee\Endpoint Security\Logs

Each module, feature, or technology places activity or debug logging in a separate file. All modules place error logging in one file, EndpointSecurityPlatform_Errors.log.

Log files

Feature or technology

File name

Platform

EndpointSecurityPlatform_Activity.log

EndpointSecurityPlatform_Debug.log

Self Protection

SelfProtection_Activity.log

SelfProtection_Debug.log

Updates

PackageManager_Activity.log

PackageManager_Debug.log

Errors

EndpointSecurityPlatform_Errors.log

Trellix Endpoint Security (ENS) Client

MFEConsole_Debug.log

Scan

OnAccessScan_Activity.log

OnAccessScan_Debug.log

OnDemandScan_Activity.log

OnAccessScan_Debug.log

Firewall

Firewall_Activity.log

Firewall_Debug.log

FirewallEventMonitor.log

FirewallEventMonitor_debug.log

Exploit Prevention

Note

Exploit Prevention is not supported in the ARM architecture.

ExploitPrevention_Activity.log

ExploitPrevention_Debug.log

Threat Prevention

ThreatPrevention_Activity.log

ThreatPrevention_Debug.log

Web Control

WebControl_Activity.log

WebControl_Debug.log



Tip

Best Practice: For information on Endpoint Security event messages, see KB85494.

By default, installation log files are stored here:

  • %TEMP%\McAfeeLogs, which is the Windows user TEMP folder. (Managed systems)

  • TEMP\McAfeeLogs, which is the Windows system TEMP folder. (Self-managed systems)