InfoCollector utility in Trellix OS:
The Info Collector utility collects and bundles essential Trellix IPS information for export or diagnosis.
To run the info collector logs, perform the following steps:
Go to Manager → <Admin Domain Name> → Troubleshooting → Info Collector.
The Info Collector page is displayed.
Go to Diagnostic Info Collector section and perform the following:
In the Include section and select the required parameters under Logs, Backups, and Files.
In the Duration section, provide the From and To dates in MM/DD/YY format.
In the Output section, provide the required File Name.
Click Start.
.jpg)
InfoCollector utility in MLOS:
To run InfoCollector, do the following:
Log in to the Manager shell using SSH.
Execute
run InfoCollector.shcommand to collect info logs.For collecting info logs by masking the sensitive information, execute
run InfoCollector.sh -anoncommand.(For InfoCollector in anonymous mode only) Select
Update configurationin the operation menu and click Enter.(For InfoCollector in anonymous mode only) Type
yand click Enter when the following question is prompted:Do you want to procced with info collector bundle creation? [y/n]
Specify the log collection start date in the format MM/DD/YYYY and pressEnter. Alternatively, just press Enter to choose the default start date (date preceding the current date).
Specify the log collection end date in the format MM/DD/YYYY and pressEnter. Alternatively, just press Enter to choose the default end date (date preceding the current date).
Select the type of log files to be collected. By default, InfoCollector collects Manager and Manager Configuration files only. However, you can control which items are collected as shown below:
For default log file, specify
yat Collect Default Items only prompt. The log bundle will be created with the filename in the formatInfoLogs<Date><time>.zipalong with success message.Tip
You can view the generated InfoCollector bundle (zip file) by executing
show filescommand.Note
By default, InfoCollector collects Manager logs and Manager configuration files only; however, you can control which items are collected.
For manually selecting custom sets of logs, specify
nat the Collect Default Items only prompt. Now, select the log files to be included in the bundle by specifyingyornone by one for each type of log.The available log types are as follows:
Manager Logs
Configuration Backups
Audit Log Backups
Manager Configuration Files
Compiled 'Sigfiles' (Sensor Deployment Binaries)
System Faults
Sensor Logs
Note
You can collect the Configuration Backups only when the InfoCollector utility is run in the normal mode.
A success message is displayed after the creation of InfoCollector bundle is completed.
Note
The InfoCollector bundle will be available at the following locations in the Manager:
/opt/IPSManager/App/diag/InfoCollector/InfoCollectorData/
/opt/scpfiles/