The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Troubleshoot issues that occur after deploying Trellix Endpoint Security (ENS) 26.x upgrades

Prev Next

After deploying an Upgrade Automation deployment task to upgrade to Trellix Endpoint Security (ENS) 26.x , use these steps to resolve problems reported in the Upgrade Automation log file on the endpoint. The Upgrade Automation software is deployed with each upgrade to manage the upgrade on the endpoint.

Upgrade Automation updates its log file for each step of the troubleshooting process.

  • In a test environment — Use these steps to ensure Upgrade Automation works correctly.

  • In your production environment — Use these steps when an Upgrade Automation task fails.

  1. On endpoints, monitor progress in the Agent Monitor, where details about the actions performed by client deployment tasks are logged.

  2. Verify that the Endpoint Upgrade Assistant package downloaded Trellix Agent and Trellix ENS. See the table below for more information.

    If Trellix Agent 4.x was installed on the endpoint before upgrading, then FOLDER PATH is C:\ProgramData\McAfee\Common Framework\[Current|Previous|Evaluation]

    If Trellix Agent 5.x was installed on the endpoint before upgrading, then FOLDER PATH is C:\ProgramData\McAfee\Agent\[Current|Previous|Evaluation]

    These folders indicate that the download was successful

    Product

    <FOLDER PATH>\ENDP_AM_1050

    <FOLDER PATH>\ENDP_AM_1060

    <FOLDER PATH>\ENDP_FW_1050

    <FOLDER PATH>\ENDP_FW_1060

    <FOLDER PATH>\ENDP_GS_1050

    <FOLDER PATH>\ENDP_GS_1060

    <FOLDER PATH>\ENDP_WP_1050

    <FOLDER PATH>\ENDP_WP_1060

    Trellix ENS 10.5 or 10.6

    <FOLDER PATH>\EPOAGENT3000

    Trellix Agent 5.0.5 or later

    <FOLDER PATH>\EUA_AUTO1000

    Upgrade Automation package (contains three .exe and two script files)

    Potential remediation step: Make sure the correct versions of Trellix Agent (version 5.0.5 or later) and Trellix ENS (version 10.5.x or 10.6) are checked in to the same branch in ePO - On-prem that the Upgrade Automation package was deployed from (for example, Current, Previous, or Evaluation).

  3. Verify that there aren't any conflicting products on the endpoint that could stop the Upgrade Automation package from running. Check the logs for this information:

    Log entry

    Indicates

    All steps completed successfully for product: ENS_HW_Requirements

    Success

    All steps completed successfully for product: ripper_conflict

    Success

    All steps completed successfully for product: ENS_RegistryConflicts

    Success

    All steps completed successfully for product: ENS_MSIConflicts

    Success

    OneBuild progress set to: COPY_FILES_COMPLETE

    Success

    All steps completed successfully for product: ENS1050_Conflicts

    Success

    All steps completed successfully for product: ENSSuccess

    Success

    Potential remediation step: Remove conflicting products and redeploy the Upgrade Automation package to the endpoint.

  4. Verify that VirusScan Enterprise and Host Intrusion Prevention policies were copied successfully on the endpoint.

    Log entry

    Indicates

    Step preserve_policy completed successfully for product: VSE 8.8

    Success

    Step preserve_policy failed for product: VSE 8.8

    Failure

    Step preserve_policy completed successfully for product: HIPS 8.0

    Success

    Step preserve_policy failed for product: HIPS 8.0

    Failure

    Potential remediation step: If an error occurs while copying policies, it does not stop the installation. After Trellix ENS is installed on the endpoint, it pulls the latest policies from ePO - On-prem.

  5. Verify that Trellix Agent upgraded successfully.

    Log entry

    Indicates

    FramePkg.exe -- SUCCESS

    Success

    FramePkg.exe -- FAIL

    Failure

    Potential remediation step: Contact Technical Support if the upgrade stops.

  6. Verify that Trellix ENS installed successfully.

    Log entry

    Indicates

    setupCC.exe succeeded

    Success

    setupCC.exe --FAIL

    Failure

    setupTP.exe succeeded

    Success

    setupTP.exe --FAIL

    Failure

    Potential remediation steps:

    • If Endpoint Upgrade Assistant closes, and reports the code 3010 and the message EUA_MFEEMPMK_UTIL_REQUIRES_REBOOT in the last line of the log file, the Trellix Exploit Prevention driver was upgraded on the endpoint. Restart the endpoint, then Endpoint Upgrade Assistant automatically resumes installing Trellix ENS.

    • Contact Technical Support if the installation stops.

  7. Verify that Upgrade Automation finished successfully.

    Log entry

    Indicates

    All steps completed successfully for product: ENSSuccess

    Success

    OneBuild exit code is 0

    Success