Configure an Analyzer
- Overview
- Prerequisites
- Windows
- Steps
- Configure Analyzer
- Deploy Analyzer
- Enable and Configure File Audit
- AWS
- Steps
- Configure Analyzer
- Deploy Analyzer
Overview
An analyzer is the component that monitors a storage location, analyzes files, takes response actions and sends alerts. Unlike the Management Service, Analyzers are deployed in the customer’s environment. Analyzers are deployed as containers or as compiled python, which can be installed as a service on Windows.
Prerequisites
You must have already defined a site in your Admin Portal.
Windows
Steps
Configure Analyzer
Currently, an analyzer needs to be added and saved before you can do a deployment. There are some server side actions that need to happen, and those aren’t triggered until you click Save on a new analyzer.
- Add a new Analyzer. In the Admin Portal, click on Analyzers, and click the
button in the top right corner.
- Enter Analyzer Name
- For Type, choose SMB
- Choose Site, Region, and Policy
- Click Save
Deploy Analyzer
- Select your Analyzer and click the Edit (pencil) icon
- Click the Deploy button
- Click the Installer button to download the installer
- Cop the installer zip file to the server you want to install onto
- Unzip the installer file
- Right click on INSTALL.ps1 and click Run as Administrator
- Follow the instructions
Enable and Configure File Audit
Instructions can be found here
AWS
Steps
Configure Analyzer
Currently, an analyzer needs to be added and saved before you can do a deployment. There are some server side actions that need to happen, and those aren’t triggered until you click Save on a new analyzer.
If you need to send the CloudFormation template to another person to install (or for approval), you can click View Template and save the file locally. If you have cloud admin permissions, you can deploy the CloudFormation template directly from the RansomStop Admin Portal.
- Add a new Analyzer. In the Admin Portal, click on Analyzers, and click the
button in the top right corner.
- Enter Analyzer Name
- For Type, choose S3
- Choose Site, Region, and Policy
- Expand the Networking section
- You will need to provide a VPC and 1-3 subnets from that VPC.
There is a convenient cloud button to take you to your AWS console so you can copy/paste the VPC and Subnet IDs. Subnet IDs should be 1 per line, max 3, no punctuation or extra characters.
- Click Save
Deploy Analyzer
- Deploy Template. Select your Analyzer
If the edit icon is green, the Analyzer has already been deployed. If it is orange, it has not yet been deployed.

- Expand the Deployment Section and click Deploy Template

- Create Stack. Click Next.

- Stack Details. Click Next.

- Stack Options. Click Acknowledge and Click Next.

- Stack Create

- Acknowledge
- Go back to the Admin Portal, to the Analyzer dialog
- Click the Policy Deployed slider and click Save