Integrate Veeam Backup & Replication
You can integrate Veeam Backup & Replication with Sophos XDR so that it sends events to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.
This integration is an on-premises-only deployment.
Key steps
The key steps in a Veeam integration are as follows:
- Install and configure a data collector if you haven't already done so.
- Configure Veeam to send data to the data collector.
- Optionally, get additional data from Veeam using the "four-eyes" feature.
Requirements
The following is required for Veeam configuration:
- You must have Veeam Backup & Replication version 12.1 or later.
- Check the requirements for the data collector you are using by reviewing the guides at Data collectors.
Add a Veeam integration
To integrate Veeam, you must first install a Sophos XDR data collector, then configure Veeam to send logs to it.
Install and configure a data collector
Veeam Backup & Replication must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.
Configure logging and enable monitoring
Once the data collector is created, you can configure Veeam Backup & Replication to send data to us.
To set up event forwarding via syslog, do as follows:
- Follow the steps in Veeam's own guide: Specifying Syslog Servers
-
Be sure to configure the following data collector details:
- IP address: The Sophos XDR data collector's server IP address
- Port: 514 or 601
Your Veeam Backup & Replication data should now appear in the Sophos Data Lake after validation.
Configuration notes
Keep the following in mind during Veeam configuration:
- You can configure multiple instances of Veeam to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of Veeam. You don't need to repeat the steps in Sophos XDR.
Get additional data from Veeam
To get data about additional Veeam events, we recommend that you turn on Veeam's four-eyes authorization.
Four-eyes authorization requires you to get additional authorization from other administrators for actions that could affect sensitive data, such as deleting backups. If you turn the feature on, details of these authorization events are sent to Sophos for analysis.
Before you turn on four-eyes authorization, check that you meet the requirements:
- You need at least two users with the Veeam Backup Administrator role. The role can be assigned to the users or to a group they're members of.
- You must configure email notifications for administrators. Veeam can then send administrators requests to approve actions. See Configuring Global Email Notification Settings.
To turn on four-eyes authorization, do as follows:
- Open the Veeam Backup & Replication console.
- From the main menu, select Users and Roles.
-
Go to the Authorization tab and do as follows:
- Select Require additional approval for sensitive operations.
- Specify the time period during which the requested operation must be approved or rejected (minimum 1 day, maximum 30).
- Click OK.
