--- title: "Managing Authorization Events" description: "Veeam App for ServiceNow allows you to monitor four-eyes authorization events from your Veeam Backup & Replication servers and create incidents when events meet specific rules." canonical: "https://helpcenter.veeam.com/archive/security_plugins_servicenow/1/guide/sn_manage_auth_events.html" breadcrumb: "User Guide > Managing Events and Incidents > Managing Authorization Events" dateModified: "2026-10-09" --- # Managing Authorization Events Veeam App for ServiceNow allows you to monitor four-eyes authorization events from your Veeam Backup & Replication servers and create incidents when events meet specific rules. For more information on events, see the [Four-Eyes Authorization](https://helpcenter.veeam.com/docs/backup/vsphere/four_eyes_authorization.html) section in the Veeam Backup & Replication User Guide. ## Viewing Authorization Events To view aggregated information on four-eyes authorization events from all your Veeam Backup & Replication servers, click **All** > **Veeam** > **Audit** > **Authorization Events**. The data is automatically updated every 30 minutes using REST API requests. To get the latest data manually, click **Collect Data**. To view detailed information on event, click the event name. [![](images/auth_events.png)](images/auth_events.png){.toggle scale=80} ## Creating Rules To create an authorization event rule that will trigger an incident, perform the following steps: 1. Click **All** > **Veeam** > **Audit** > **Authorization Event Rules**. 2. Click **New**. 3. Fill in the following fields if applicable: - **Caller** — incident reporter. - **Service** — affected business service. - **Category** — incident type. - **Impact** — measure of the incident effect. - **Urgency** — how long the resolution can be delayed until an incident has a significant business impact. - **Assignment Group** — user group to work on the incident. - **Additional Description** — specific details related to the incident. 4. In the **Conditions** section, specify rule conditions that will trigger the incident. 5. Click **Submit**. To view information on all created incidents, click **All** > **Veeam** > **Audit** > **Incidents**. ::: tip By default, an incident contains minimum event details displayed in the **Correlation ID** and **Description** fields. To provide more details, link the authorization event fields with the incident built-in or custom fields in the **Field Mapping** section. ::: [![](images/auth_events_rule.png)](images/auth_events_rule.png){.toggle scale=80}