DRS Precheck Failure:
The precheck logs can be found by checking the logs of the pod malware-analysis-vc-precheck-vcenter-cluster-drs-*.
For example, when DRS is set to fully automated:
2026-08-06 22:27:33,949 - precheck - INFO - OpenSSL version: OpenSSL 3.5.5 27 Jan 2026; FIPS mode: True2026-08-06 22:27:33,950 - precheck - INFO - Invoking precheck vcenter_cluster_drs2026-08-06 22:27:33,950 - malware_analysis_precheck - INFO - Running precheck PrecheckName.vcenter_cluster_drs for feature malware-analysis-vc2026-08-06 22:27:35,858 - malware_analysis_precheck - WARNING - Expected a vmotionRate of 5, but it is 1.2026-08-06 22:27:35,858 - malware_analysis_precheck - INFO - Precheck PrecheckName.vcenter_cluster_drs completed: CheckStatus.FAILED2026-08-06 22:27:35,996 - malware_analysis_precheck - INFO - Precheck PrecheckName.vcenter_cluster_drs for feature malware-analysis-vc completed: CheckStatus.FAILED2026-08-06 22:27:36,046 - precheck - INFO - Precheck vcenter_cluster_drs completed: failed
Security Services Platform (SSP) 5.2.0 with phase 1 of MPS installed
The prechecks for MPS Phase 2 fails when the vCenter cluster has incorrect DRS settings configured.
The Sandbox Detonation of MPS requires very specific DRS settings on its Cluster as we do not want DRS to interfere with the LCM running on SSP that manages the detonation environment and VMs:
The DRS settings of the Cluster selected for Sandbox Detonation must be set as described.
Automation Level - Manual
Migration Threshold - 1 - Conservative (Less Frequent vMotion)
Predictive DRS - Disable
Virtual Machine Automation - Enable
Additional Options: Default (None enabled)
Power Management: Default (None Enabled)
Advanced Options: None