Skip to main content
Question

Threat Scan 11.44+ – Windows vs Linux Threat Scan Server requirements

  • September 30, 2026
  • 3 replies
  • 40 views

Nikos.Kyrm
Community All Star
Forum|alt.badge.img+17

Hi everyone,

First of all, I have to say that Threat Scan in 11.44+ feels like a completely different product compared to 11.40. The improvements are significant, and the addition of VM workloads to the Threat Scan capabilities is a really nice enhancement.
 

While going through the 11.44 documentation, I came across the following:

“For Windows VM workloads, set up a Windows Threat Scan server.”
“For Linux VM workloads, set up a Linux Threat Scan server.”

Commvault Threat Scan Requirements
 

My question is regarding whether this OS-specific requirement applies only to VM workloads, or also to File System workloads.

For example, if an environment contains both Windows and Linux File System workloads, can we use a Windows Threat Scan server to scan both, or would we need separate Windows and Linux Threat Scan servers?

In other words, is the Windows/Linux Threat Scan server distinction specifically related to the way VM disks/filesystems are mounted and accessed during VM Threat Scan, or does the same restriction apply to regular File System Threat Scan as well?

This is a relatively new area for many of us, so it would be useful to have a clear clarification on the expected architecture.
 

Please for your feedback,
Nikos

3 replies

Hi ​@Nikos.Kyrm 

This distinction is for VM workloads only, more context on the background of this can be found under the Advanced Requirements section, 

https://documentation.commvault.com/11.44/software/commvault_threat_scan_advanced_requirements.html#file-system-support-for-vm-workloads

 

Those restrictions are based on the Live Browse nature of ThreatScan 2.0 when dealing with VM workloads, as we no longer need to restore the full VM as it was handled before in TS1.0, you can find similar restrictions for the normal VM guest file browse operations on the below docs

While you can use a Linux TS node for windows file system workloads and vice versa, it’s generally better to have homogenous OS setup ~ but that’s not a requirement as of now.

Thanks,

Abdu


Nikos.Kyrm
Community All Star
Forum|alt.badge.img+17
  • Author
  • Community All Star
  • October 5, 2026

Dear ​@AbdulRahman AlSindiony 

Thanks a lot for your reply! 


One more question regarding the recommended architecture:

Would you recommend using a dedicated MediaAgent / Threat Scan server for Threat Scan? I am asking because I noticed that Threat Scan 11.44+ seems to have relatively low CPU utilization compared to Threat Scan v1. 

Could I use our 4-node HyperScale X cluster as the Threat Analysis / Threat Scan servers for Linux VM workloads? Are there any specific limitations or recommendations regarding using HyperScale X nodes for this purpose?


Thank you in advance,
Nikos


Hi ​@Nikos.Kyrm ,

Not recommended, but possible to do.

 

If you have cloud library to run ThreatScan against, it would be better to leverage the AutoScaling feature, it’s very great with ThreatScan 2.0 (TS2.0)

Auto-scaling for Access Nodes

 

A dedicated ThreatScan server is better to go with

File indexing and Threat Analysis processes do not recognize when backup operations are running on proxies. Because these processes are resource-intensive, they can negatively impact backup performance and delay job completion. To avoid performance issues, do not overlap proxies used for Threat Analysis jobs with those used for backup jobs. The access nodes defined at the Threat Analysis plan level should be different from the proxies configured for backups (defined at the hypervisor or VM group level).

Commvault Threat Scan Requirements

 

Thanks,

Abdu