Hello, everyone. I'm having an issue with the HIPS log not updating. I'm on Patch 11 and the issue is occuring on a Server 2012 R2 system.
I've tried uninstalling and reinstalling HIPS, reducing the log file size in the Client UI policy, and rebooting the systems.
Any suggestions? I have zero visibility into what HIPS and its firewall are doing.
Solved! Go to Solution.
You might have an issue where the HIPS services aren't running (McAfee Host Intrusion Prevention lpc Service and McAfee Host Intrusion Prevention Service; HIPS may not be active, so no logging is generated), or possibly the "C:\ProgramData\McAfee\Host Intrusion Prevention\Event.log" file is corrupt and can't be written to (this is the file represented as the Activity log).
You might try deleting that file (stop the HIPS services first), then restart the HIPS services.
If that doesn't work , please open a Service Request with our McAfee Support team for further investigation; please include a full debug MER file for review.
Do you have the logging options enabled in the Activity log? Make sure they are all enabled.
If you enable HIPS debug logging (via policy or registry), you should still see firewall traffic in the debug Firesvc.log file (although it will be more detailed than the Activity log).
Yes, I have all boxes checked just like in your screenshot. Any ideas on how to get the Activity log to work again?
You might have an issue where the HIPS services aren't running (McAfee Host Intrusion Prevention lpc Service and McAfee Host Intrusion Prevention Service; HIPS may not be active, so no logging is generated), or possibly the "C:\ProgramData\McAfee\Host Intrusion Prevention\Event.log" file is corrupt and can't be written to (this is the file represented as the Activity log).
You might try deleting that file (stop the HIPS services first), then restart the HIPS services.
If that doesn't work , please open a Service Request with our McAfee Support team for further investigation; please include a full debug MER file for review.
Deleting the Event.log file and restarting the services fixed it. Thank you!
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA