Managing Incidents

You can manage Veeam App for Palo Alto Networks XSOAR incidents manually or using Veeam playbooks.

Managing Incidents Manually

After you resolve the incident on the Veeam Backup & Replication or Veeam ONE integration instance, you need to close it in Veeam App for Palo Alto Networks XSOAR. To do this, perform the following steps:

  1. On the Incident Info tab, click Actions > Close incident.
  2. Select the close reason and specify close notes if required.
  3. Click Close Incident.

After you close the incident, it will disappear from the Veeam Backup & Replication Active Incidents or Veeam ONE Active Incidents widget.

Managing Incidents with Playbooks

For specific incidents, you can use Veeam playbooks:

Managing Incidents with Playbooks

Playbook Name

Applicable to

Description

Veeam — Start Configuration Backup

Configuration Backup incidents.

Starts configuration backup job for the Veeam Backup & Replication integration instance. When the job finishes with the Warning or Success state, the incident will be automatically closed.

Veeam — Start Instant VM Recovery Automatically

Incidents based on Veeam Backup & Replication malware events and the Recon Scanner threat state alarm.

Starts the Instant Recovery session with automatic configuration. The playbook automatically gets the latest clean restore point and the name of the restored virtual machine, defines the folder and the ESXi host, and starts the Instant Recovery session. You can also enable the antivirus scan during the session.

If the playbook cannot automatically define the folder and the ESXi host, you can start the Instant Recovery session with manual configuration and specify the required parameters explicitly.

When the session finishes with the Warning or Success state, you need to finish the migration in the Veeam Backup & Replication console and close the incident manually.

Note: The playbook runs the veeam-vbr-get-inventory-objects command to get required inventory information from the Veeam Backup & Replication integration instance. This command contains custom parameters and cannot be run as a single command in the Cortex XSOAR command-line interface.

For more information about the command, see this article in the Cortex XSOAR Reference.

Veeam — Start Instant Hyper-V VM Recovery Automatically

Incidents based on Veeam Backup & Replication malware events and the Recon Scanner threat state alarm.

Starts the Instant Recovery session with automatic configuration. The playbook automatically gets the latest clean restore point and the name of the restored virtual machine, defines the folder and the Microsoft Hyper-V host, and starts the Instant Recovery session. You can also enable the antivirus scan during the session.

If the playbook cannot automatically define the folder and the Microsoft Hyper-V host, you can start the Instant Recovery session with manual configuration and specify the required parameters explicitly.

When the session finishes with the Warning or Success state, you need to finish the migration in the Veeam Backup & Replication console and close the incident manually.

Note: The playbook runs the veeam-vbr-get-inventory-objects command to get required inventory information from the Veeam Backup & Replication integration instance. This command contains custom parameters and cannot be run as a single command in the Cortex XSOAR command-line interface.

For more information about the command, see this article in the Cortex XSOAR Reference.

Veeam — Start Instant VM Recovery Manually

Incidents based on Veeam Backup & Replication malware events and the Recon Scanner threat state alarm.

Starts the Instant Recovery session with manual configuration. The playbook automatically gets the latest clean restore point and the name of the restored virtual machine. To start the Instant Recovery session, you need to specify parameters required for the API request.

When the session finishes with the Warning or Success state, you need to finish the migration in the Veeam Backup & Replication console and close the incident manually.

Veeam — Start Instant Hyper-V VM Recovery Manually

Incidents based on Veeam Backup & Replication malware events and the Recon Scanner threat state alarm.

Starts the Instant Recovery session with manual configuration. The playbook automatically gets the latest clean restore point and the name of the restored virtual machine. To start the Instant Recovery session, you need to specify parameters required for the API request.

When the session finishes with the Warning or Success state, you need to finish the migration in the Veeam Backup & Replication console and close the incident manually.

Veeam — Start Security & Compliance Analyzer

Security & Compliance Analyzer and Backup Server Security Status incidents.

Starts Security & Compliance Analyzer scan for the Veeam Backup & Replication integration instance.

Veeam — Start Scan Backup

Incidents based on Veeam Backup & Replication malware events and the Recon Scanner threat state alarm.

Starts a Scan Backup session with manual configuration. To start the session, you need to specify parameters required for the API request including a restore point and a scan engine.

Veeam — Start Quick Backup

Incidents related to data backup.

Starts a Quick Backup session for a VMware vSphere VM. The playbook automatically gets the name of the virtual machine.

Veeam — Start Disk Publishing

Incidents related to data recovery.

The playbook gets the latest restore point of the virtual machine and starts disk publishing using the specified mount server.

Veeam — Stop Disk Publishing

Incidents related to data recovery.

Stops disk publishing.

Veeam — Find Entra ID User

Incidents related to Microsoft Entra ID backup.

Checks if a user exists in the latest Microsoft Entra ID tenant backup.

Veeam — Compare Entra ID Items

Incidents related to Microsoft Entra ID backup.

Compares Microsoft Entra ID item properties between the latest restore point and production.

Veeam — Resolve Triggered Alarms

Incidents based on Veeam ONE alarms.

Resolves or acknowledges Veeam ONE triggered alarms. For resolved alarms, the playbook also automatically closes the incident.