Veeam Backup Integration
Overview
Veeam provides data protection for virtual, physical, and cloud workloads. KYRA MDR collects Veeam backup logs for monitoring operations and detecting ransomware indicators. Supports Veeam 11 and 12.
Prerequisites
- A KYRA MDR Collector installed and running
- Veeam Backup & Replication server
- Administrative access to the Veeam console
- Windows Event Forwarding or NXLog for log collection
Configuration
Configure Veeam event collection:
- Veeam writes events to the Windows Application Event Log
- Install NXLog on the Veeam server:
<!-- nxlog.conf --><Input in_veeam> Module im_msvistalog Query <QueryList>\ <Query Id="0">\ <Select Path="Veeam Backup">*</Select>\ </Query>\ </QueryList></Input>
<Output out_kyra> Module om_tcp Host <collector-ip> Port 514 Exec to_syslog_bsd();</Output>
<Route 1> Path in_veeam => out_kyra</Route>- Restart the NXLog service
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Backup Jobs | Backup success and failure events | Data protection monitoring |
| Restore Jobs | Restore operation events | Recovery auditing |
| Repository | Storage repository events | Storage health monitoring |
| SureBackup | Backup verification results | Backup integrity validation |
| Configuration | Setting and job changes | Change management |
| Security | Authentication and access events | Infrastructure security |
Troubleshooting
No Veeam events: Verify the Veeam Backup event log exists in Windows Event Viewer.
Missing job details: Query the “Veeam Backup” log specifically, not the Application log.
Ransomware detection: Sudden backup failures across multiple jobs may indicate ransomware.
Contact kyra@seekerslab.com for support.