Veeam Backup & Replication
You can integrate Veeam Backup & Replication with Sophos XDR so that it sends events to Sophos for analysis.
This page gives you an overview of the integration.
Veeam Backup & Replication product overview
Veeam Backup & Replication is a comprehensive data protection and disaster recovery solution. With Veeam Backup & Replication, you can create image-level backups of virtual, physical, and cloud machines and restore from them. The technology used in the product optimizes data transfer and resource consumption, helping minimize storage costs and recovery time in the event of a disaster.
What we ingest
We ingest syslog from Veeam Backup & Replication (messages tagged Veeam_MP) as sent to the integration. Messages are retained and searchable in the Sophos XDR Data Lake alongside other telemetry.
Most events are normalized to cloud audit–style telemetry (administrative and security-relevant change activity). Additional processing enriches specific Veeam event types with structured fields such as users, targets, change details, and authentication outcomes. Some events are also represented as authentication telemetry (multi-factor authentication failures and lockouts) or antivirus-style telemetry (malware detection resolution), while remaining available in cloud audit form where applicable.
Event and data types
We ingest the following event and data types from Veeam Backup & Replication:
- Backup credential lifecycle: Credential records added, updated, or deleted.
- Failed add of user or group: Failed attempt to add a user or group.
- Failed backup deletion from client: Unsuccessful attempt to delete backup from a reported client endpoint.
- SureBackup job deleted: Removal of a SureBackup job.
- SSH options for credentials updated: SSH-related credential options changed, including before/after property detail when logged.
- Object location changed: Protected object location change with prior and new location context when present.
- Multi-factor authentication (MFA) administration: MFA enabled or disabled (globally or per user), MFA token reset.
- Invalid MFA code: Invalid MFA code entered; also normalized to authentication telemetry.
- Account locked (MFA): Account locked after repeated invalid MFA codes; also normalized to authentication telemetry.
- Four-eyes authorization: Four-eyes mode and approval workflow events (enabled/disabled, pending, approved, rejected, expired).
- KMS server and key management: KMS server added, removed, or reconfigured; KMS key rotation session completion.
- Malware detection resolved: Malware detection outcome resolved (for example, marked clean or false positive) and normalized to antivirus-style telemetry (and cloud audit where applicable).
Note
Veeam syslog uses vendor instance ID. The categories above correspond to those IDs in the Veeam event reference.
Data provided by this integration
Data provided by Veeam Backup & Replication gets normalized to the following schemas:
antivirusauthcloudaudit
For more information about using schemas in Data Lake Search, see Schemas and logical types.