--- title: "Incident Reference" description: "Veeam App for Palo Alto Networks XSOAR supports the following incident types:" canonical: "https://helpcenter.veeam.com/docs/security_plugins_xsoar/guide/xsoar_incident_reference.html" breadcrumb: "User Guide > Working with Incidents > Incident Reference" dateModified: "2026-09-07" --- # Incident Reference Veeam App for Palo Alto Networks XSOAR supports the following incident types:
|
Source |
Incident Type |
Description |
Severity |
|---|---|---|---|
|
Veeam Backup & Replication |
Configuration Backup |
Incident based on the date of the last successful Veeam Backup & Replication configuration backup. |
Medium |
|
Veeam Backup & Replication |
Malware Detection — Antivirus Scan |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Deleted Files |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Encrypted Files |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Indicators of Compromise |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Ransomware Notes |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Renamed Files |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Suspicious Files and Extensions |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Unknown |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Malware Detection — Yara Scan |
Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference. |
High or Critical |
|
Veeam Backup & Replication |
Security & Compliance Analyzer |
Incident based on the results of the Veeam Security & Compliance Analyzer scan. For more details, see Security & Compliance Analyzer. |
Critical |
|
Veeam Backup & Replication |
SureBackup — Backup Verification and Content Scan |
Incident based on the result of the SureBackup job run in the Backup verification and content scan only mode. |
High |
|
Veeam Backup & Replication |
Repository Capacity |
Incident based on the backup repository free space. |
High |
|
Veeam ONE |
Backup Copy Creation Time |
Incident based on the Backup Copy RPO alarm. For more details, see Veeam Backup & Replication Alarms. |
Critical |
|
Veeam ONE |
Backup Server Security Status |
Incident based on the Backup Server security & compliance state alarm. For more details, see Veeam Backup & Replication Alarms. |
Medium |
|
Veeam ONE |
Enterprise Application Backup |
Incident based on the Application with no recent data backup sessions alarm. For more details, see Veeam Backup & Replication Alarms. |
Critical |
|
Veeam ONE |
Immutability Change Tracking |
Incident based on the Immutability change tracking alarm. For more details, see Veeam Backup & Replication Alarms. |
Medium |
|
Veeam ONE |
Immutability State |
Incident based on the Immutability state alarm. For more details, see Veeam Backup & Replication Alarms. |
Medium |
|
Veeam ONE |
Incremental Backup Size |
Incident based on the Suspicious incremental backup size alarm. For more details, see Veeam Backup & Replication Alarms. |
Critical |
|
Veeam ONE |
Job Disabling |
Incident based on the Job disabled alarm. For more details, see Veeam Backup & Replication Alarms. |
Medium |
|
Veeam ONE |
Job Duration |
Incident based on the Unusual job duration alarm. For more details, see Veeam Backup & Replication Alarms. |
Medium |
|
Veeam ONE |
Job Duration Deviation (Veeam Backup for Microsoft 365) |
Incident based on the Unusual job duration (Veeam Backup for Microsoft 365) alarm. For more details, see Veeam Backup for Microsoft 365 Alarms. |
Medium |
|
Veeam ONE |
Malware Detection Change Tracking |
Incident based on the Veeam malware detection change tracking alarm. For more details, see Veeam Backup & Replication Alarms. |
Critical |
|
Veeam ONE |
Physical Machine Backup |
Incident based on the Computer with no backup alarm. For more details, see Veeam Backup & Replication Alarms. |
Critical |
|
Veeam ONE |
Possible Malware Activity |
Incident based on the Potential malware in backups alarm. For more details, see Veeam Backup & Replication Alarms. |
Critical |
|
Veeam ONE |
Recon Threat State |
Incident based on the Recon Scanner threat state alarm. For more details, see Internal Alarms. |
Critical |
|
Veeam ONE |
Virtual Machine Backup |
Incident based on the VM with no backups alarm. For more details, see VMware vSphere Alarms and Microsoft Hyper-V Alarms. |
Critical |
|
Veeam ONE |
Virtual Machine Replica |
Incident based on the VM with no replica alarm. For more details, see VMware vSphere Alarms and Microsoft Hyper-V Alarms. |
Critical |
|
Veeam App for Palo Alto Networks XSOAR |
Incident Fetch Error |
Incident based on Veeam REST APIs availability. |
Medium |