Use logs to troubleshoot and resolve issues of Trellix Application and Change Control.
Log file locations
Log files and its location details are shared below:
Installation logs — Solidcore_Installer.log, solidcore_setup.log, mac_mpt.log, and mac_mpt.etl
Windows OSes — %SYSTEMROOT (for example, C:\Windows \)
Product logs — Solidcore.log and S3diag.log (C:\ProgramData\McAfee\SolidcoreC:\ProgramData\McAfee\Solidcore)
Log file size and count
To increase the log file size (in MB), run this command:
sadmin config set LogfileSize=XXXX
To increase the number of rotated log files, run this command:
sadmin config set LogfileNum=X
Common log level changes
At times, increasing log levels in the Trellix Application and Change Control product is needed to troubleshoot an issue. When the module logging levels are increased, reset the logging back to the default levels. For example, if a module and level is set to ENABLE, run the same command with DISABLE to undo the increase in logging.
Available log 'TYPES' — ERROR, WARNING, SYSTEM, INFO, DETAIL, FNENTRY, and FNEXIT
Default levels for all modules — ERROR, WARNING, and SYSTEM
For information about Minimum Data Collection to troubleshoot Trellix Application and Change Control, see KB90755.
Some common log levels and related troubleshooting areas are given below:
Log level | Troubleshooting area |
|---|---|
sadmin loglevel enable swin info detail | TACC driver framework |
sadmin loglevel enable mahdlr all | Trellix Agent interactions with the TACC product |
sadmin loglevel enable sau info detail | Sau (script as updater) module |
sadmin loglevel enable usm info | Trellix® Data Exchange Layer responsiveness |
sadmin loglevel enable inv info | Inventory module |
sadmin loglevel enable pst info | Memory protection module |
sadmin loglevel enable ruleengine info | TACC execution control module |
sadmin loglevel enable cctl info detail | Binary execution based on Trellix GTI reputation of its certificate |
sadmin loglevel enable rbl info detail | Reputation workflows (Trellix GTI) |
sadmin loglevel enable cert info | Certificate module |
sadmin loglevel enable evt info | Events |
sadmin loglevel enable fmon info | File monitoring |