After deploying an Upgrade Automation deployment task to upgrade to Trellix Endpoint Security (ENS) 26.x , use these steps to resolve problems reported in the Upgrade Automation log file on the endpoint. The Upgrade Automation software is deployed with each upgrade to manage the upgrade on the endpoint.
Upgrade Automation updates its log file for each step of the troubleshooting process.
In a test environment — Use these steps to ensure Upgrade Automation works correctly.
In your production environment — Use these steps when an Upgrade Automation task fails.
On endpoints, monitor progress in the Agent Monitor, where details about the actions performed by client deployment tasks are logged.
Verify that the Endpoint Upgrade Assistant package downloaded Trellix Agent and Trellix ENS. See the table below for more information.
If Trellix Agent 4.x was installed on the endpoint before upgrading, then FOLDER PATH is
C:\ProgramData\McAfee\Common Framework\[Current|Previous|Evaluation]If Trellix Agent 5.x was installed on the endpoint before upgrading, then FOLDER PATH is
C:\ProgramData\McAfee\Agent\[Current|Previous|Evaluation]These folders indicate that the download was successful
Product
<FOLDER PATH>\ENDP_AM_1050
<FOLDER PATH>\ENDP_AM_1060
<FOLDER PATH>\ENDP_FW_1050
<FOLDER PATH>\ENDP_FW_1060
<FOLDER PATH>\ENDP_GS_1050
<FOLDER PATH>\ENDP_GS_1060
<FOLDER PATH>\ENDP_WP_1050
<FOLDER PATH>\ENDP_WP_1060
Trellix ENS 10.5 or 10.6
<FOLDER PATH>\EPOAGENT3000
Trellix Agent 5.0.5 or later
<FOLDER PATH>\EUA_AUTO1000
Upgrade Automation package (contains three .exe and two script files)
Potential remediation step: Make sure the correct versions of Trellix Agent (version 5.0.5 or later) and Trellix ENS (version 10.5.x or 10.6) are checked in to the same branch in ePO - On-prem that the Upgrade Automation package was deployed from (for example, Current, Previous, or Evaluation).
Verify that there aren't any conflicting products on the endpoint that could stop the Upgrade Automation package from running. Check the logs for this information:
Log entry
Indicates
All steps completed successfully for product: ENS_HW_Requirements
Success
All steps completed successfully for product: ripper_conflict
Success
All steps completed successfully for product: ENS_RegistryConflicts
Success
All steps completed successfully for product: ENS_MSIConflicts
Success
OneBuild progress set to: COPY_FILES_COMPLETE
Success
All steps completed successfully for product: ENS1050_Conflicts
Success
All steps completed successfully for product: ENSSuccess
Success
Potential remediation step: Remove conflicting products and redeploy the Upgrade Automation package to the endpoint.
Verify that VirusScan Enterprise and Host Intrusion Prevention policies were copied successfully on the endpoint.
Log entry
Indicates
Step preserve_policy completed successfully for product: VSE 8.8
Success
Step preserve_policy failed for product: VSE 8.8
Failure
Step preserve_policy completed successfully for product: HIPS 8.0
Success
Step preserve_policy failed for product: HIPS 8.0
Failure
Potential remediation step: If an error occurs while copying policies, it does not stop the installation. After Trellix ENS is installed on the endpoint, it pulls the latest policies from ePO - On-prem.
Verify that Trellix Agent upgraded successfully.
Log entry
Indicates
FramePkg.exe -- SUCCESS
Success
FramePkg.exe -- FAIL
Failure
Potential remediation step: Contact Technical Support if the upgrade stops.
Verify that Trellix ENS installed successfully.
Log entry
Indicates
setupCC.exe succeeded
Success
setupCC.exe --FAIL
Failure
setupTP.exe succeeded
Success
setupTP.exe --FAIL
Failure
Potential remediation steps:
If Endpoint Upgrade Assistant closes, and reports the code 3010 and the message EUA_MFEEMPMK_UTIL_REQUIRES_REBOOT in the last line of the log file, the Trellix Exploit Prevention driver was upgraded on the endpoint. Restart the endpoint, then Endpoint Upgrade Assistant automatically resumes installing Trellix ENS.
Contact Technical Support if the installation stops.
Verify that Upgrade Automation finished successfully.
Log entry
Indicates
All steps completed successfully for product: ENSSuccess
Success
OneBuild exit code is 0
Success