--- title: "Incident Reference" description: "Veeam App for Palo Alto Networks XSOAR supports the following incident types:" canonical: "https://helpcenter.veeam.com/docs/security_plugins_xsoar/guide/xsoar_incident_reference.html" breadcrumb: "User Guide > Working with Incidents > Incident Reference" dateModified: "2026-09-07" --- # Incident Reference Veeam App for Palo Alto Networks XSOAR supports the following incident types:

Source

Incident Type

Description

Severity

Veeam Backup & Replication

Configuration Backup

Incident based on the date of the last successful Veeam Backup & Replication configuration backup.

Medium

Veeam Backup & Replication

Malware Detection — Antivirus Scan

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Deleted Files

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Encrypted Files

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Indicators of Compromise

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Ransomware Notes

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Renamed Files

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Suspicious Files and Extensions

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Unknown

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Malware Detection — Yara Scan

Incident based on the Veeam Backup & Replication malware event. For more details, see the Malware Activity Detected event in the Event Reference.

High or Critical

Veeam Backup & Replication

Security & Compliance Analyzer

Incident based on the results of the Veeam Security & Compliance Analyzer scan. For more details, see Security & Compliance Analyzer.

Critical

Veeam Backup & Replication

SureBackup — Backup Verification and Content Scan

Incident based on the result of the SureBackup job run in the Backup verification and content scan only mode.

High

Veeam Backup & Replication

Repository Capacity

Incident based on the backup repository free space.

High

Veeam ONE

Backup Copy Creation Time

Incident based on the Backup Copy RPO alarm. For more details, see Veeam Backup & Replication Alarms.

Critical

Veeam ONE

Backup Server Security Status

Incident based on the Backup Server security & compliance state alarm. For more details, see Veeam Backup & Replication Alarms.

Medium

Veeam ONE

Enterprise Application Backup

Incident based on the Application with no recent data backup sessions alarm. For more details, see Veeam Backup & Replication Alarms.

Critical

Veeam ONE

Immutability Change Tracking

Incident based on the Immutability change tracking alarm. For more details, see Veeam Backup & Replication Alarms.

Medium

Veeam ONE

Immutability State

Incident based on the Immutability state alarm. For more details, see Veeam Backup & Replication Alarms.

Medium

Veeam ONE

Incremental Backup Size

Incident based on the Suspicious incremental backup size alarm. For more details, see Veeam Backup & Replication Alarms.

Critical

Veeam ONE

Job Disabling

Incident based on the Job disabled alarm. For more details, see Veeam Backup & Replication Alarms.

Medium

Veeam ONE

Job Duration

Incident based on the Unusual job duration alarm. For more details, see Veeam Backup & Replication Alarms.

Medium

Veeam ONE

Job Duration Deviation (Veeam Backup for Microsoft 365)

Incident based on the Unusual job duration (Veeam Backup for Microsoft 365) alarm. For more details, see Veeam Backup for Microsoft 365 Alarms.

Medium

Veeam ONE

Malware Detection Change Tracking

Incident based on the Veeam malware detection change tracking alarm. For more details, see Veeam Backup & Replication Alarms.

Critical

Veeam ONE

Physical Machine Backup

Incident based on the Computer with no backup alarm. For more details, see Veeam Backup & Replication Alarms.

Critical

Veeam ONE

Possible Malware Activity

Incident based on the Potential malware in backups alarm. For more details, see Veeam Backup & Replication Alarms.

Critical

Veeam ONE

Recon Threat State

Incident based on the Recon Scanner threat state alarm. For more details, see Internal Alarms.

Critical

Veeam ONE

Virtual Machine Backup

Incident based on the VM with no backups alarm. For more details, see VMware vSphere Alarms and Microsoft Hyper-V Alarms.

Critical

Veeam ONE

Virtual Machine Replica

Incident based on the VM with no replica alarm. For more details, see VMware vSphere Alarms and Microsoft Hyper-V Alarms.

Critical

Veeam App for Palo Alto Networks XSOAR

Incident Fetch Error

Incident based on Veeam REST APIs availability.

Medium