Windows

Overview

This section describes how to install and configure MetaDefender (MD) Cluster File Storage service on Windows system. After installation, MD Cluster Control Center can connect to MD Cluster File Storage and monitor its system health.


Prerequisites

Before installing the MD Cluster File Storage service, ensure the following requirements are met.

Requirement

Description

Operating System

Windows 11 23H2+, or Windows Server 2019+.

Privileges

Administrator privileges.

Installation package

md-cluster-file-storage-<version>-1-x64.msi

Network access

Required port is open (default port: 8890).

A minimum network bandwidth of 1 Gbps is required.

A bandwidth of 5 Gbps or higher is strongly recommended in the following scenarios:

  • Load shared among MetaDefender Core instances for archive processing.

  • CDR or DLP is enabled.

Hardware

8 vCPU and 8GB RAM

Disk space

Use SSD storage with high read/write throughput for optimal performance.

A minimum of 1 TB of available disk space is required. If CDR or DLP is enabled:

  • Additional disk capacity may be required due to increased processing and storage demands.

  • It is recommended to enable data retention to manage stored files effectively.


Create the ignition file

Create an ignition file in YAML format. This file contains the credentials required for the service to connect to the system.

The file must include the following keys:

Key

Description

secure.connection_key

A 4–64 character alphanumeric string (a–z, A–Z, 0–9) used by MD Cluster Control Center to connect to the server.

secure.private_key

The content of private key in X509 format.

secure.certificate

The content of certificate in X509 format.

Example ignition file:

secure:
connection_key: "1234abcd" # [0-9a-zA-Z]{4,64}
private_key: |
-----BEGIN PRIVATE KEY-----
MIIJQwIBADANBgkqhkiG9w0BAQEFAASCCS0wggkpAgEAAoICAQCjYtuWaICCY0tJ
PubxpIgIL+WWmz/fmK8IQr11Wtee6/IUyUlo5I602mq1qcLhT/kmpoR8Di3DAmHK
nSWdPWtn1BtXLErLlUiHgZDrZWInmEBjKM1DZf+CvNGZ+EzPgBv5nTekLWcfI5ZZ
toGuIP1Dl/IkNDw8zFz4cpiMe/BFGemyxdHhLrKHSm8Eo+nT734tItnHKT/m6DSU
0xlZ13d6ehLRm7/+Nx47M3XMTRH5qKP/7TTE2s0U6+M0tsGI2zpRi+m6jzhNyMBT
J1u58qAe3ZW5/+YAiuZYAB6n5bhUp4oFuB5wYbcBywVR8ujInpF8buWQUjy5N8pS
Np7szdYsnLJpvAd0sibrNPjC0FQCNrpNjgJmIK3+mKk4kXX7ZTwefoAzTK4l2pHN
uC53QVc/EF++GBLAxmvCDq9ZpMIYi7OmzkkAKKC9Ue6Ef217LFQCFIBKIzv9cgi9
fwPMLhrKleoVRNsecBsCP569WgJXhUnwf2lon4fEZr3+vRuc9shfqnV0nPN1IMSn
zXCast7I2fiuRXdIz96KjlGQpP4XfNVA+RGL7aMnWOFIaVrKWLzAtgzoGMTvP/Au
ehKXncBJhYtW0ltTioVx+5yTYSAZWl+IssmXjefxJqYi2/7QWmv1QC9psNcjTMaB

Save the ignition file to the following path on the target machine:

C:\opswat\md_cluster_file_storage.yml
Info

The ignition file contains sensitive credentials. This file can be safely deleted any time after the installation is complete.


Install the service

  1. Copy the installer file (.msi ) to the target machine.

  2. Open PowerShell with Administrator privileges.

  3. Run the following command to start the installation in silent mode:

msiexec.exe /i <md_cluster_file_storage_package>.msi /qn

Verify the service status

  1. Open PowerShell and run the following command:

Get-Service -Name md-cluster-file-storage
  1. Check the Running Status in the output.

  2. If the service is not running, start it manually:

Start-Service -Name md-cluster-file-storage

Service management

Action

Command

Check service status

Get-Service -Name md-cluster-file-storage

Start service

Start-Service -Name md-cluster-file-storage

Stop service

Stop-Service -Name md-cluster-file-storage

Restart service

Restart-Service -Name md-cluster-file-storage


Customize the service configuration

During installation, MD Cluster File Storage service generates a configuration file at:

C:\Program Files\OPSWAT\MetaDefender Cluster File Storage\md_cluster_file_storage.yml

To customize the service behavior:

  1. Open the configuration file in a text editor.

  2. Modify the required settings according to your environment.

  3. Save the changes.

  4. Restart the service to apply the new settings.

Restart-Service -Name md-cluster-file-storage

Directory structure

  • C:\opswat\md_cluster_file_storage.yml: Service Ignition file.

  • C:\Program Files\OPSWAT\MetaDefender Cluster File Storage\md_cluster_file_storage.yml: Service configuration file.

  • C:\Program Files\OPSWAT\MetaDefender Cluster File Storage\data\log\file-storage.log: Service log file.

  • C:\Program Files\OPSWAT\MetaDefender Cluster File Storage\data\storage: Default storage directory.


Log files

To check the service logs, open the file C:\Program Files\OPSWAT\MetaDefender Cluster File Storage\data\log\file-storage.log.

To check logs using Event Viewer:

  1. Open Event Viewer.

  2. Navigate to Windows Logs > Application.

  3. Look for events related to MD Cluster File Storage Service.


Uninstall the service

Open PowerShell and run the following command:

Uninstall-Package -Name 'MetaDefender Cluster File Storage' -Force
Warning

If storage.path is not set in the Ignition file, the storage directory will be deleted when MD Cluster File Storage is uninstalled.


Troubleshooting

A. Service is not running

  1. Check the service status

Get-Service -Name md-cluster-file-storage
  1. Start the service if it is not running:

Start-Service -Name md-cluster-file-storage

B. Installation fails

Possible causes

  • Insufficient privileges.

  • Missing dependencies.

Solution

  • Ensure the installation command is executed with Administrator privileges.

  • Ensure dependencies are installed.

C. MD Cluster Control Center cannot connect to MD Cluster File Storage.

Possible causes

  • Network connectivity issues.

  • Firewall restrictions.

Solution

  • Ensure MD Cluster Control Center has network connectivity to MD Cluster File Storage.

  • Verify that firewall rules allow inbound and outbound connections.


Ignition file key reference

  • secure.connection_key (Required)

    • Value type: string.

    • Description: Use a 4–64 character string that contains only numbers (0–9) and letters (a–z, A–Z). This string is used by clients to connect to the server. Set this value as the identity.connection_key in the MD Cluster Control Center configuration file.

  • secure.private_key (Required)

    • Value type: string.

    • Description: The content of private key in X509 format.

  • secure.certificate (Required)

    • Value type: string.

    • Description: The content of certificate in X509 format.

  • storage.path (optional)

    • Value type: string.

    • Description: Path to an existing directory where the MD Cluster File Storage server stores its files. On Linux, the server must have full permissions to access this directory.

  • rest.host [optional)

    • Value type: string.

    • Description: IP address (V4/V6) or host where the server resides on. Default value is '*'. Notes: '*' allows the service to accept connections from all network interfaces. To bind the service to a specific interface, specify its IP address or domain name. For example, to listen on all IPv4 interfaces, set the host to 0.0.0.0.

  • rest.port [optional)

    • Value type: number.

    • Description: The port where the server resides on. Default value is 8890.

  • log.streams[@].log_type [optional)

    • Value type: string.

    • Description: Type of log device (file, or syslog)

  • log.streams[@].log_level [optional)

    • Value type: string.

    • Description: Level of log message (dump, debug, info, warning, or error).

  • log.streams[@].log_path [optional)

    • Value type: string.

    • Description: Location where logs are written. If log.streams[@].log_type is "file" then log.streams[@].log_path is the path to a file on file system where logs are written. If log.streams[@].log_type is "syslog" then

      • log.streams[@].log_path can be [tcp/udp]://host:port where host:port is the host and port to a remote syslog server that supports TCP or UDP protocol.

      • log.streams[@].log_path can be "local" to write log to local syslog server (Linux only).

Info

If storage.path is not set in the Ignition file, MD Cluster File Storage saves submitted files to the default storage directory at C:\Program Files\OPSWAT\MetaDefender Cluster File Storage\data\storage