The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Using Symbolic Links for Agent Program Data in Windows Environments

Prev Next

You can use a Windows file system junction, or symbolic link, for the agent data stored in the Windows ProgramData folder (C:\%ProgramData%\FireEye).

If you choose to use a symbolic link, consider the following caveats:

  • Symbolic links are supported for Endpoint Security (HX) version 20 or later. This functionality has not been tested with earlier versions.

  • This functionality is supported by the agent only for Windows 7 64-bit systems.

  • Agents cannot share symbolic link locations, which means no network shares can be used. Each host endpoint must have its own symbolic link.

  • Set up the symbolic link before installing the agent software.

For information about setting up symbolic links in Windows environments, refer to your Microsoft Windows system internals documentation (https://technet.microsoft.com/en-us/sysinternals/bb896768.aspx).