The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Trellix Endpoint Security (ENS) 26.x installation files

Prev Next

The Trellix Endpoint Security (ENS) 26.x installer tracks details about installation, uninstallation, and migration in log files that you can use to verify results and troubleshoot problems.

Default location of installation log files

By default, the installer saves the installation log files to this location:

When...

Log location

Path

Deploying remotely (using ePO - On-prem, Endpoint Upgrade Assistant, or a third-party tool)

Windows System TEMP folder

C:\Windows\TEMP\McAfeeLogs

Running the installer locally on the endpoint

User TEMP folder — %Temp%\McAfeeLogs

C:\Users\username\AppData\Local\Temp\McAfeeLogs

Endpoint users must have permission to access the file.

The path for the installation log location can include case-sensitive folders. After installation, the Trellix ENS self-protection feature prevents changing the case sensitivity of the endpoint log location configured in the Common Options policy or moving the log location to a case-sensitive folder.

Changing the location of installation log files

Use one of these command-line options to change the location for the log files:

/log"install_log_path"

/l"install_log_path"

/l*v"install_log_path"

where:

  • "install_log_path" — Specifies where to save the installation log files.

    The installer creates an Endpoint folder at the specified location and saves the log files to this folder.

  • *v — Specifies verbose (more descriptive) logging entries.

Example

/l"D:\Log Files"

Installs the product log files under D:\Log Files\EndPoint\.

Support for case sensitivity (Microsoft Windows 10 October 2018 Update or later)

The installer can save logs to a folder with a case-sensitive path. After installation, the Trellix ENS self-protection feature prevents you from changing the case sensitivity of the Trellix ENS client log location configured in the Common Options policy or moving that log location to a case-sensitive folder.

Installation and migration log files

Check these log files for details about installation and migration.

Log file name

Type of information

McAfee_<module>_Install_<%timestamp%>.log

Installation log for each product module.

McAfee_<Module>_Bootstrapper_<%timestamp%>.log

Bootstrapper for each product module.

McAfee_Endpoint_BootStrapper_<%timestamp%>.log

Bootstrapper for the Master installer (SetupEP) on self-managed systems.

McAfee_<Module>_CustomAction_Install_<%timestamp%>.log

MSI Custom Action for each product module.

McAfee_Endpoint_CompetitorUninstaller.log

Removal of incompatible virus-protection and firewall products.

McAfee_Endpoint_Security_Migration_xxx.log

Removal of legacy products.

Example: McAfee_Endpoint_Security_Migration_McAfee VirusScan Enterprise_8.8_06042015195245175.log

McAfee_<module>_Migration_Plugin.log

Preserve and restore status of migrated legacy settings, per module.

Example: McAfee_TP_Migration_Plugin.log

McAfee_ESP_Migration_Plugin.log

Legacy settings migrated to the Common Options policy.

Uninstallation log files

Check these log files for details about removing the product.

Log file name

Type of information

McAfee_<Module>_UnInstall<%timestamp%>.log

Uninstallation log for each product module.

McAfee_<Module>_CustomAction_Uninstall<%timestamp%>.log

MSI Custom Action for each product module for uninstallation.

McAfee_CommonUninst<%timestamp%>.log

Uninstallation log for Common module (which is uninstalled with last product module).

McAfee_ Common_VScore_Uninstall<%timestamp%>.log

Log for VSCore driver removal by Common module.

McAfee_ Firewall_FireCore_Uninstall<%timestamp%>.log

Log for FireCore driver removal by Common module. (Created only for versions 10.5.2 and earlier.)

McAfee_ ThreatPrevention_Caspercore_Uninstall<%timestamp%>.log

Log for CasperCore driver removal by Threat Prevention.

McAfee_ ThreatPrevention_ELAM_AVDriver_Uninstall<%timestamp%>.log

Log for ELAM driver removal by Threat Prevention. (Created only for versions 10.5.2 and earlier.)

McAfee_ ThreatPrevention_EP_Uninstall<%timestamp%>.log

Log for Exploit Prevention removal by Threat Prevention. (Created only for versions 10.5.2 and earlier.)