--- title: "Adding Veeam Backup & Replication Instances" description: "To add a Veeam Backup & Replication integration instance, perform the following steps: In the main menu, click Settings. On the Integrations > Instances tab, search the Veeam Backup & Replication REST API (Partner Contribution) integration and..." canonical: "https://helpcenter.veeam.com/docs/security_plugins_xsoar/guide/xsoar_vbr_instances_configure.html" breadcrumb: "User Guide > Working with Instances > Configuring Instances > Adding Veeam Backup & Replication Instances" dateModified: "2026-09-07" --- # Adding Veeam Backup & Replication Instances To add a Veeam Backup & Replication integration instance, perform the following steps: 1. In the main menu, click **Settings**. 2. On the **Integrations** > **Instances** tab, search the **Veeam Backup & Replication REST API (Partner Contribution)** integration and click **Add instance**. 3. In the **Connect** section, specify the following settings: - **Name** — a name of the Veeam Backup & Replication instance. For example, *VBRSRV01*. - **Credentials** — credentials you use to connect to the Veeam Backup & Replication REST API. Must have administrator privileges and multi-factor authentication (MFA) disabled. For more information, see [Disabling MFA for Service Accounts](https://helpcenter.veeam.com/docs/backup/vsphere/mfa.html?#disabling-mfa-for-service-accounts) in the Veeam Backup & Replication User Guide. - **Resource URL** — URL that you use to connect to the Veeam Backup & Replication REST API: - Format — *\:\* - Default port number — *9419* or *443* (for Veeam Backup & Replication v13.1 and later) - **API Request Timeout (Seconds)** — timeout for Veeam Backup & Replication REST API requests. The default value is *120*. - **API Version** — a Veeam Backup & Replication REST API version and revision. The default value is *1.2-rev0*. ::: note Other settings should be specified according to your infrastructure. ::: 4. In the **Collect** section, specify the following settings: - **Fetches incidents** — enables fetching incidents from the instance. Data is displayed on the Veeam Incident Dashboard. - **Classifier** — a name of the integration incident classifier. By default, *Veeam Backup & Replication Incidents Classifier* is used. To customize the default classifier, find it on the **Settings** > **Objects Setup** > **Incidents** > **Classification and Mapping** tab, make a copy and edit integration incident types. Then, select the new classifier in the instance settings. ::: tip You can also create a new classifier for integration incident types. ::: - **Mapper (Incoming)** — a name of the integration mapper for incoming incidents. By default, *Veeam Backup & Replication Incoming Mapper* is used. To customize the default mapper, find it on the **Settings** > **Objects Setup** > **Incidents** > **Classification and Mapping** tab, make a copy and edit mapping between event attributes and integration incident types. Then, select the new mapper in the instance settings. - **First Fetch Time** — a time period that defines how far back in time incidents will be fetched from the instance for the first time. The default value is *3 days*. - **Fetch configuration backup events** — enables monitoring for incidents based on the date of the last configuration backup. An incident will be created if there are no successful configuration backups for the period specified in the **Days Since Last Configuration Backup** field. The default value is *30*. If you do not want to monitor this incident type, clear the check box. - **Fetch backup repository events** — enables monitoring for incidents based on the disk usage of the backup repository. An incident will be created if the free space size is less than the amount of GB specified in the **Backup Repository Free Space (GB)** field. The default value is *200*. In the **Backup Repository Events Per Request** field, you can specify the maximum number of incidents that can be created per fetch. The default value is *39*. If you do not want to monitor this incident type, clear the check box. - **Fetch malware events** — enables monitoring for incidents based on Veeam Backup & Replication malware events. In the **Malware Events Per Request** field, you can specify the maximum number of incidents that can be created per fetch. The default value is *160*. If you do not want to monitor this incident type, clear the check box. - **Fetch Security & Compliance Analyzer events** — enables monitoring for incidents based on Security & Compliance Analyzer scan results. For more information, see [Security & Compliance Analyzer](https://helpcenter.veeam.com/docs/vbr/userguide/best_practices_analyzer.html) in the Veeam Backup & Replication User Guide. If you do not want to monitor this incident type, clear the check box. - **Fetch SureBackup job events** — enables monitoring for incidents based on the result of the SureBackup job run in the *Backup verification and content scan only* mode. For more information, see [SureBackup Job](https://helpcenter.veeam.com/docs/vbr/userguide/surebackup_job.html) in the Veeam Backup & Replication User Guide. If you do not want to monitor this incident type, clear the check box. ::: important Fetching SureBackup job events is not supported for Veeam Backup & Replication 12. If you use this version, you must clear the check box to avoid incident fetch errors. ::: - **Incidents Fetch Interval** — a time interval for fetching new incidents from the instance. The default value is *10 minutes*. 5. To check the connection to the Veeam Backup & Replication REST API, click **Test**. 6. If the check is successful, click **Save & exit**. Fetching incidents will start automatically. ::: tip To view fetch history, select the instance and click the history icon. ::: ![](images/xsoar_vbr_instance_add.png)