View and manage events in an unmanaged environment

Prev Next

Application Control generates events when an action is taken to change or execute a file on a protected system. You can review and manage events to monitor the status of the unmanaged endpoints.

Go the Trellix Agent icon on your desktop and select Quick SettingsApplication and Change Control Events.

You can see a list with all events generated for that endpoint.

You can manage event logging separately by enabling the s3diag feature. This log helps in deciding the updaters list.

To enable event logging, run this command:

#sadmin s3diag-on

Note

By default, this feature is disabled.

To disable event logging, run this command:

#sadmin s3diag-off

You can find event logs at this location: /var/log/mcafee/solidcore/s3diag.log