Logger policy configuration

Prev Next

You can configure how devices log Trellix EDR client service events.

Option definitions

Option

Definition

Logger format

Select None to stop Trellix EDR from creating logs. Select File to create logs in files. Logs are stored in the following locations:

  • Windows: %systemdrive%\ProgramData\McAfee\Mar\data\mar.log

  • Linux: /var/McAfee/Mar/data/mar.log and /var/McAfee/mvedr/trace/data/trace.log

  • macOS: /var/McAfee/Mar/data/mar.log

Log level

  • Debug — Logs fine-grained events useful to identify problems with Trellix EDR client execution.

  • Trace — Logs almost all variable value dumps. This can be too verbose to debug problems on production systems.

  • Info — The default level. It logs messages that highlight the progress of the Trellix EDR client service.

  • Warning — Logs potentially harmful situations.

  • Error — Logs errors that cause Trellix EDR client service to end.

Note

Use the lowest log level when possible, or disable this feature if you do not need log information.

Click Show advanced to display other policy options.

Buffer size

The number of messages that the logger holds in a buffer before saving to the log file. If set to 1, Trellix EDR updates the log file immediately after each message is generated.

The default value set is 20. The minimum and maximum value you can set is between 1 and 120.

Maximum size of the log file (MB)

Maximum size of Trellix EDR log files.

The default value set is 10 MB. The minimum and maximum value you can set is between 10 and 100 MB.