Correlation Rule Templates
This section contains the list of Veeam correlation rule templates with recommended settings and examples of XQL search queries. For more details on how to add a correlation, see Adding Correlations.
Allowed Attempts for Multi-Factor Authentication Exceeded
Rule Name: Allowed Attempts for Multi-Factor Authentication Exceeded Rule Description: Sent when a user exceeds the allowed number of attempts for multi-factor authentication. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Archive Repository Deleted
Rule Name: Archive Repository Deleted Rule Description: Sent when a user deletes an archive repository from the backup infrastructure. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Attempt to Delete Backup Failed
Rule Name: Attempt to Delete Backup Failed Rule Description: Sent when a user with insufficient privileges tries to delete a backup file. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Attempt To Update Security Object Failed
Rule Name: Attempt To Update Security Object Failed Rule Description: Sent when a user with insufficient privileges tries to update a security object including users and roles, credential records, certificates, or passwords. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Backup Repository Deleted
Rule Name: Backup Repository Deleted Rule Description: Sent when a user deletes a backup repository from the backup infrastructure. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Connection to Backup Repository Lost
Rule Name: Connection to Backup Repository Lost Rule Description: Sent when a backup server fails to connect to a backup repository. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Credential Record Deleted
Rule Name: Credential Record Deleted Rule Description: Sent when a user deletes a credential record. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Encryption Password Deleted
Rule Name: Encryption Password Deleted Rule Description: Sent when a user deletes an encryption password. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
External Repository Deleted
Rule Name: External Repository Deleted Rule Description: Sent when a user deletes an external repository from the backup infrastructure. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Four-Eyes Authorization Disabled
Rule Name: Four-Eyes Authorization Disabled Rule Description: Sent when a user disables four-eyes authorization. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Four-Eyes Authorization Request Created
Rule Name: Four-Eyes Authorization Request Created Rule Description: Sent when a user creates a four-eyes authorization request. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Rule Name: Job Deleted Rule Description: Sent when a user deletes a job. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
KMS Server Deleted
Rule Name: KMS Server Deleted Rule Description: Sent when a user exceeds the allowed number of attempts for multi-factor authentication. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Malware Activity Detected
Rule Name: Malware Activity Detected Rule Description: Sent when malware activity is detected. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Malware Detection Settings Updated
Rule Name: Malware Detection Settings Updated Rule Description: Sent when a user updates malware detection settings. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: High Category: Other |
Multi-Factor Authentication Disabled
Rule Name: Multi-Factor Authentication Disabled Rule Description: Sent when a user disables multi-factor authentication for all users. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Multi-Factor Authentication for User Disabled
Rule Name: Multi-Factor Authentication for User Disabled Rule Description: Sent when a user disables multi-factor authentication for a specific user if it is used as a service account. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Object Storage Deleted
Rule Name: Object Storage Deleted Rule Description: Sent when a user deletes an object storage repository from the backup infrastructure. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
Storage Deleted
Rule Name: Storage Deleted Rule Description: Sent when a user deletes a storage appliance from the backup infrastructure. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |
User or Group Deleted
Rule Name: User or Group Deleted Rule Description: Sent when a user deletes a user or a user group. XQL Search:
Time Schedule: Every 10 minutes Action: Generate alert Alert Domain: Security Severity: Critical Category: Other |