The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Threat Prevention log file names and locations

Prev Next

The activity, error, and debug log files record events that occur on systems with Endpoint Security enabled.

All activity and debug log files are stored in the following default location:

%ProgramData%\McAfee\Endpoint Security\Logs

Each module, feature, or technology places activity or debug logging in a separate file. All modules place error logging in one file, EndpointSecurityPlatform_Errors.log.

Enabling debug logging for any module also enables debug logging for the Common module features, such as Self Protection.

Log files

Module

Feature or technology

File name

Threat Prevention

Enabling debug logging for any Threat Prevention technology also enables debug logging for the Trellix Endpoint Security (ENS) Client.

ThreatPrevention_Activity.log

ThreatPrevention_Debug.log

Exploit Prevention

Note

Exploit Prevention is not supported in the ARM architecture.

ExploitPrevention_Activity.log

ExploitPrevention_Debug.log

On-Access Scan

OnAccessScan_Activity.log

OnAccessScan_Debug.log

On-Demand Scan

  • Quick Scan

  • Full Scan

  • Right-Click Scan

OnDemandScan_Activity.log

OnDemandScan_Debug.log

Access Protection

AccessProtection_Activity.log

AccessProtection_Debug.log

Common

EndpointSecurityPlatform_Errors.log

Contains error logs for all modules.



Tip

Best practice: For information on Endpoint Security event messages, see KB85494.

By default, installation log files are stored here:

  • TEMP\McAfeeLogs, which is the Windows system TEMP folder. (Managed systems)

  • %TEMP%\McAfeeLogs, which is the Windows user TEMP folder. (Self-managed systems)