Viewing Trellix Agent logs

Prev Next

The Trellix Agent log is a condensed log that can be viewed from the client system.

Trellix Agent Status Monitor — You can open the Trellix Agent Status Monitor window from the Trellix Agent tray icon (McTray).

Single System Troubleshooting — You can view the Trellix Agent logs of a managed system from the ePO - On-prem console remotely for troubleshooting. SST allows you to retrieve logs for both the Agent and integrated point products. The Zipped log file size limit for product logs is 50 MB by default, and can be adjusted up to 200 MB in the Trellix Agent policy under the Product logging section in Logging tab.

You can enable remote logging by enabling the Enable Remote Logging option under the General policy Logging tab. The default line limit for the remote log is 200 lines and can go up to 5000 lines.

Trellix Agent product logs — You can record all Trellix Agent activities related to policy enforcement, agent-server communication, product deployment, update logging, and event forwarding in the respective log files.

You can configure the Logging policy options under the General policy tab to enable Trellix Agent logging on the managed systems and ePO - On-prem. Configuring the Application Logging option allows Trellix Agent to record the activities in the Trellix Agent log files. In addition to the information stored in the Trellix Agent log, you can view detailed log that contains troubleshooting messages. You can enable detailed logging by enabling the Enable detailed logging option. The default file size is 2 MB and can go up to 100 MB. The default rollover count is 1 and can go up to 10. In Trellix Agent versions 5.7.7 to 5.8.2, the maximum file size of McScript.log is 10 MB and 10 rollover counts. From version 5.8.3 and later, the file size limit and the number of rollover counts are based on the settings defined in the assigned policy.

You can view all installation-related activities in the installation log files.

By default, the Trellix Agent logs on Windows client systems are saved in <ProgramData>\McAfee\Agent\Logs.

The Windows installation logs on the client system are saved in:

  • %TEMP%\McAfeeLogs, if the Trellix Agent is installed or upgraded manually.

  • C:\Windows\Temp\McAfeeLogs, if Trellix Agent is installed using push or deployment task on ePO - On-prem.

The Non-Windows installation logs on client system are saved in /var/log/ if Trellix Agent is installed using Trellix Smart Installer.

Whenever there is a manifest integrity failure or an error in the policy database validation, the Trellix Agent logs an error message in the mapolicy_<hostname>.log file. The maximum file size is 5 MB for 1 rollover count and there is no impact on this file size by the Trellix Agent policy.

The table lists the Trellix Agent logs and installation log files for Windows and Non-Windows client systems.

Trellix Agent logs (Windows)

Trellix Agent logs (Non-Windows)

Installation logs (Windows)

Installation logs (Non-Windows)

masvc_<hostname>.log

masvc_<hostname>.log

Frminst_<hostname>.log

McAfeeSmartInstall_<system time stamp>.log

macmnsvc_<hostname>.log

macmnsvc_<hostname>.log

Frminst_<hostname>_error.log

mcupdater_<hostname>.log

macompatsvc_<hostname>.log

macompatsvc_<hostname>.log

MFEAgent.msi.<system time stamp>.log

McScript.log

McScript.log

McAfeeSmartInstall_<system time stamp>.log

McScript_error.log

McScript_error.log

mcupdater_<hostname>.log

McScript_deploy.log

McScript_deploy.log

McScript_deploy_error.log

McScript_deploy_error.log

marepomirror.log

mcupdater_<hostname>.log

marepomirror_error.log

McAfeeSmartInstall_<system time stamp>.log

UpdaterUI_<hostname>.log

UpdaterUI_<hostname>_error.log

McTray_<hostname>.log

mfemactl.log

mfemactl_c.log

mapolicy_<hostname>.log

mapolicy_<hostname>.log

dxl-installer.log

dxl-installer.log

MCAFEE_AGENT_UNINSTALL.log