跳至正文

Veeam Backup Integration

Overview

Veeam provides data protection for virtual, physical, and cloud workloads. KYRA MDR collects Veeam backup logs for monitoring operations and detecting ransomware indicators. Supports Veeam 11 and 12.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Veeam Backup & Replication server
  • Administrative access to the Veeam console
  • Windows Event Forwarding or NXLog for log collection

Configuration

Configure Veeam event collection:

  1. Veeam writes events to the Windows Application Event Log
  2. Install NXLog on the Veeam server:
<!-- nxlog.conf -->
<Input in_veeam>
Module im_msvistalog
Query <QueryList>\
<Query Id="0">\
<Select Path="Veeam Backup">*</Select>\
</Query>\
</QueryList>
</Input>
<Output out_kyra>
Module om_tcp
Host <collector-ip>
Port 514
Exec to_syslog_bsd();
</Output>
<Route 1>
Path in_veeam => out_kyra
</Route>
  1. Restart the NXLog service

Collected Log Types

Log TypeDescriptionSecurity Use
Backup JobsBackup success and failure eventsData protection monitoring
Restore JobsRestore operation eventsRecovery auditing
RepositoryStorage repository eventsStorage health monitoring
SureBackupBackup verification resultsBackup integrity validation
ConfigurationSetting and job changesChange management
SecurityAuthentication and access eventsInfrastructure security

Troubleshooting

No Veeam events: Verify the Veeam Backup event log exists in Windows Event Viewer.

Missing job details: Query the “Veeam Backup” log specifically, not the Application log.

Ransomware detection: Sudden backup failures across multiple jobs may indicate ransomware.

Contact kyra@seekerslab.com for support.