The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Upgrade Automation and Endpoint Upgrade Assistant Package Creator files

Prev Next

Events that occur during upgrades to Trellix Endpoint Security (ENS) 26.x that are managed using Endpoint Upgrade Assistant are reported in the Upgrade Automation log file on the endpoints where they occur. Additionally, Package Creator reports events related to generating or deploying custom installation packages to the same log file.

The Upgrade Automation software, which is deployed to endpoints during upgrades to manage the upgrades, creates the Upgrade Automation log file at this location: %windir%\Temp\McAfeeLogs\EndpointUpgradeAutomation.log

You can specify a new location when you create an Upgrade Automation deployment task or custom installation package.

More than one product component might report entries to the Upgrade Automation log during the upgrade process.

When you do this...

Upgrade Automation log file location is...

Notes

Create a custom package or installer

On the endpoint where you run Package Creator

Package Creator generates the log file.

Deploy a custom package using ePO - On-prem

On the endpoint you deploy the upgrade to

Upgrade Automation generates the log file.

If you deploy to the same endpoint where you created the custom package, Upgrade Automation appends data to the log file created by Package Creator.

Deploy a custom installer using a third-party tool

On the endpoint you deploy the upgrade to

The installer uses the same product removal and installer logic as Upgrade Automation, and generates a log file with the same name and a similar signature as Upgrade Automation.

If you deploy to the same endpoint where you generated the custom installer, the product installer appends data to the data it already reported in the log file.