Troubleshooting and logs

Prev Next

Use logs to troubleshoot and resolve issues of Trellix Application and Change Control.

Log file locations

Log files and its location details are shared below:

  • Installation logs — Solidcore_Installer.log, solidcore_setup.log, mac_mpt.log, and mac_mpt.etl

  • Windows OSes — %SYSTEMROOT (for example, C:\Windows \)

  • Product logs — Solidcore.log and S3diag.log (C:\ProgramData\McAfee\SolidcoreC:\ProgramData\McAfee\Solidcore)

Log file size and count

To increase the log file size (in MB), run this command:

sadmin config set LogfileSize=XXXX

To increase the number of rotated log files, run this command:

sadmin config set LogfileNum=X

Common log level changes

At times, increasing log levels in the Trellix Application and Change Control product is needed to troubleshoot an issue. When the module logging levels are increased, reset the logging back to the default levels. For example, if a module and level is set to ENABLE, run the same command with DISABLE to undo the increase in logging.

Available log 'TYPES' — ERROR, WARNING, SYSTEM, INFO, DETAIL, FNENTRY, and FNEXIT

Default levels for all modules — ERROR, WARNING, and SYSTEM

For information about Minimum Data Collection to troubleshoot Trellix Application and Change Control, see KB90755.

Some common log levels and related troubleshooting areas are given below:

Log level

Troubleshooting area

sadmin loglevel enable swin info detail

TACC driver framework

sadmin loglevel enable mahdlr all

Trellix Agent interactions with the TACC product

sadmin loglevel enable sau info detail

Sau (script as updater) module

sadmin loglevel enable usm info

Trellix® Data Exchange Layer responsiveness

sadmin loglevel enable inv info

Inventory module

sadmin loglevel enable pst info

Memory protection module

sadmin loglevel enable ruleengine info

TACC execution control module

sadmin loglevel enable cctl info detail

Binary execution based on Trellix GTI reputation of its certificate

sadmin loglevel enable rbl info detail

Reputation workflows (Trellix GTI)

sadmin loglevel enable cert info

Certificate module

sadmin loglevel enable evt info

Events

sadmin loglevel enable fmon info

File monitoring