We're planning to install the Huntress EDR agent on both nodes of a 2-node hyperconverged cluster. Before we touch production, I'd like to hear from anyone running Huntress, or a similar EDR, on StarWind nodes.
Environment
- 2 × Dell R640, Windows Server 2022 Datacenter, Hyper-V Failover Cluster
- StarWind VSAN Free, Windows-native service (not the CVM), managed through StarWindX PowerShell
- Build 8.0.0.20089, upgraded from 20084 in July
- One HA device, about 7 TB, all-flash, direct-connect 25GbE sync/iSCSI links between the nodes
- L1 write-back cache disabled on both nodes, per StarWind's recommendation after the incident described below
- A separate third server provides the cluster witness and Hyper-V Replica target
- Workload: a handful of server VMs (DCs, file, application) plus about 14 Windows 11 VDI VMs
In July, StarWindService.exe crashed twice within about 7 hours on build 20084. The Event 1000 entries showed ntdll.dll, exception 0xc0000374. The second crash hit the sync source while a resync was still running, which left both nodes "not synchronized." We recovered with MarkAsSynchronized() from SyncHaDevice.ps1, thanks to help on this forum. We then upgraded to 20089 and disabled the cache, and it has been stable since. So I'm being very careful about anything that hooks into the StarWind service or the storage path.
What we plan to do
- Install the agent on one node per night: drain the node with Suspend-ClusterNode, install, verify, then resume. Do the second node only after 24 clean hours on the first.
- Exclude both nodes and the witness from Huntress's automatic host isolation. Isolation would cut the sync and iSCSI traffic.
- Add Microsoft Defender exclusions:
- the StarWindService.exe process
- C:\Program Files\StarWind Software\
- the folder holding the .img and header files (S:\StarWind)
- C:\ClusterStorage\
- C:\Windows\Cluster\
- Confirm with Get-MpPreference that the exclusions persist after Huntress's managed Defender policy applies.
- Has anyone run Huntress EDR on StarWind VSAN nodes? Any crashes, sync drops, iSCSI latency or failover problems?
- Is there a current official StarWind antivirus/EDR exclusion list for Windows-native VSAN on Hyper-V? Is anything missing from mine above, such as the log folder or other StarWind processes?
- Should StarWindService.exe also be excluded from EDR process monitoring and injection, not just from AV file scanning?
- Is there any recommended StarWind-side setting to adjust, such as sync or heartbeat timeouts, when adding a security agent to the nodes?