Playbook Reference

The table below lists playbooks supported by Veeam App for Microsoft Sentinel.

Playbook Name

Applicable to

Description

Veeam-PerformConfigurationBackupOnIncident

Incidents or analytics rules based on Veeam Backup & Replication configuration backup events:

  • Configuration Backup Failed
  • Configuration Backup Job Failed

Starts a configuration backup job for the Veeam Backup & Replication server.

Veeam-StartQuickBackup

Incidents or analytics rules based on the Malware Event Detected event.

Starts a Quick Backup session for the backup object.

Veeam-PerformScanBackup

Incidents or analytics rules based on the Malware Event Detected event.

Starts an antivirus scan session for the restore point.

Veeam-FindCleanRestorePoints

Incidents or analytics rules based on the Malware Event Detected event.

Checks if there are clear restore points for the backup object.

Veeam-PerformInstantVMRecovery

Incidents or analytics rules based on the Malware Event Detected event.

Starts the VM Instant Recovery session. When the session finishes with the Warning or Success state, you need to finish the migration in the Veeam Backup & Replication console.

Veeam-ResolveTriggeredAlarms

Incidents or analytics rules based on Veeam ONE alarms.

Resolves Veeam ONE triggered alarms.