Veeam App (v2.0.0)

The Veeam Apps allow Veeam Data Platform Advanced and Premium customers to combine the automation and orchestration features of the Cortex product suite with a simple and powerful Veeam Data Platform that goes beyond backup providing businesses with reliable data protection, seamless recovery, and streamlined data management.

Author
Veeam Software
Support
partner
URL
https://www.veeam.com/support.html
Default data source
VBR REST API
Categories
Vulnerability Management

Incident fields (33)

Integrations (2)

Layouts (6)

Scripts (4)

XSIAM Dashboards (2)

XSIAM Reports (7)

README

Overview

The Veeam Apps for Palo Alto Networks bring backup intelligence into Cortex XSIAM and Cortex XSOAR. Backup and security events, recovery context, and response actions all arrive in the SOC, so security teams can enrich threat detection, investigate faster, and coordinate response and recovery without leaving the workflows they already use. Available to Veeam Data Platform Advanced and Premium customers.

<~XSOAR>
Security teams rarely have visibility into what is happening inside the backup environment. Malware detections, suspicious restore activity, configuration changes, and compliance gaps sit in tools owned by backup administrators, so they never reach the SOC — and analysts lose time chasing that context in the middle of an incident.

The Veeam App for Palo Alto Networks Cortex XSOAR helps close that gap. It uses the Veeam Backup & Replication and Veeam ONE REST API to create incidents for malware detections, suspicious activity, and the health of your backup infrastructure. Analysts can triage incidents from the built-in Veeam Incident Dashboard and initiate predefined actions through built-in playbooks, without opening a backup console or handing the ticket to a backup administrator.

The content pack includes:

Generic access to supported Veeam Backup & Replication REST API endpoints to extend the existing VBR integration with custom investigations and workflows (new in v2).

Documentation

Veeam Helpcenter User Guide

Screenshots

The XSOAR Dashboard

Veeam - Start Instant VM Recovery Automatically
</~XSOAR>
<~XSIAM>
Security teams rarely have visibility into what is happening inside the backup environment. Malware detections, suspicious restore activity, configuration changes, and compliance gaps sit in tools owned by backup administrators, so they never reach the SOC, and analysts lose time chasing that context in the middle of an incident.

The Veeam App for Palo Alto Networks Cortex XSIAM helps close that gap by bringing Veeam backup and security events into Cortex XSIAM, where they can be analyzed alongside endpoint, identity, and network events to enrich threat detection and investigations. Analysts can also initiate predefined Veeam actions directly from Cortex workflows. It works with:

Monitoring & Security Visibility

The app gets information from the event forwarding capabilities via syslog servers integrated with Veeam Backup & Replication and Veeam ONE, parses the data and displays it on the Veeam Data Platform Monitoring dashboard. For events and alarms with Medium, High and Critical severity, the app displays them on the Veeam Security Activities dashboard.
It includes:

Information:\
Consider the following:

Response Actions & Playbooks

Analysts can initiate predefined Veeam playbooks directly from Veeam incidents, including:

Documentation

Veeam Helpcenter User Guide for XSIAM Monitoring

The documentation also includes examples of correlation rules for Veeam security activities.

Screenshots

The Security Dashboard

The Monitoring Dashboard
</~XSIAM>