The activity, error, and debug log files record events that occur on systems with Trellix products enabled.
All activity and debug log files are stored here:
%ProgramData%\McAfee\Endpoint Security\Logs
Each module, feature, or technology places activity or debug logging in a separate file. All modules place error logging in one file, EndpointSecurityPlatform_Errors.log.
Feature or technology | File name |
|---|---|
Platform | EndpointSecurityPlatform_Activity.log |
EndpointSecurityPlatform_Debug.log | |
Self Protection | SelfProtection_Activity.log |
SelfProtection_Debug.log | |
Updates | PackageManager_Activity.log |
PackageManager_Debug.log | |
Errors | EndpointSecurityPlatform_Errors.log |
Trellix Endpoint Security (ENS) Client | MFEConsole_Debug.log |
Scan | OnAccessScan_Activity.log |
OnAccessScan_Debug.log | |
OnDemandScan_Activity.log | |
OnAccessScan_Debug.log | |
Firewall | Firewall_Activity.log |
Firewall_Debug.log | |
FirewallEventMonitor.log | |
FirewallEventMonitor_debug.log | |
Exploit Prevention
| ExploitPrevention_Activity.log |
ExploitPrevention_Debug.log | |
Threat Prevention | ThreatPrevention_Activity.log |
ThreatPrevention_Debug.log | |
Web Control | WebControl_Activity.log |
WebControl_Debug.log |
Tip
Best Practice: For information on Endpoint Security event messages, see KB85494.
By default, installation log files are stored here:
%TEMP%\McAfeeLogs, which is the Windows user TEMP folder. (Managed systems)
TEMP\McAfeeLogs, which is the Windows system TEMP folder. (Self-managed systems)