Linux: /var/McAfee/Mar/data/mar.log and /var/McAfee/mvedr/trace/data/trace.log
macOS: /var/McAfee/Mar/data/mar.log
Log level
Debug — Logs fine-grained events useful to identify problems with Trellix EDR client execution.
Trace — Logs almost all variable value dumps. This can be too verbose to debug problems on production systems.
Info — The default level. It logs messages that highlight the progress of the Trellix EDR client service.
Warning — Logs potentially harmful situations.
Error — Logs errors that cause Trellix EDR client service to end.
Note
Use the lowest log level when possible, or disable this feature if you do not need log information.
Click Show advanced to display other policy options.
Buffer size
The number of messages that the logger holds in a buffer before saving to the log file. If set to 1, Trellix EDR updates the log file immediately after each message is generated.
The default value set is 20. The minimum and maximum value you can set is between 1 and 120.
Maximum size of the log file (MB)
Maximum size of Trellix EDR log files.
The default value set is 10 MB. The minimum and maximum value you can set is between 10 and 100 MB.
Data Loss Prevention (DLP) > Data Loss Prevention On-prem > Trellix Data Loss Prevention 11.11.x Product Guide > Appendix > Policy Catalog settings > Mac OS X Client Configuration