--- title: "Adding Veeam ONE Instances" description: "To add a Veeam ONE integration instance, perform the following steps: In the main menu, click Settings. On the Integrations > Instances tab, search the Veeam ONE REST API (Partner Contribution) integration and click Add instance." canonical: "https://helpcenter.veeam.com/docs/security_plugins_xsoar/guide/xsoar_vone_instances_configure.html" breadcrumb: "User Guide > Working with Instances > Configuring Instances > Adding Veeam ONE Instances" dateModified: "2026-09-07" --- # Adding Veeam ONE Instances To add a Veeam ONE integration instance, perform the following steps: 1. In the main menu, click **Settings**. 2. On the **Integrations** > **Instances** tab, search the **Veeam ONE REST API (Partner Contribution)** integration and click **Add instance**. 3. In the **Connect** section, specify the following settings: - **Name** — a name of the Veeam ONE instance. For example, *VONESRV01*. - **Credentials** — credentials you use to connect to the Veeam ONE REST API. Must have administrator privileges and multi-factor authentication (MFA) disabled. - **Resource URL** — URL that you use to connect to the Veeam ONE REST API: - Format — *\:\* - Default port number — *1239* - **API Request Timeout (Seconds)** — timeout for Veeam ONE REST API requests. The default value is *120*. ::: note Other settings should be specified according to your infrastructure. ::: 4. In the **Collect** section, specify the following settings: - **Fetches incidents** — enables fetching incidents from the instance. Data is displayed on the Veeam Incident Dashboard. - **Classifier** — a name of the integration incident classifier. By default, *Veeam ONE Incidents Classifier* is used. To customize the default classifier, find it on the **Settings** > **Objects Setup** > **Incidents** > **Classification and Mapping** tab, make a copy and edit integration incident types. Then, select the new classifier in the instance settings. ::: tip You can also create a new classifier for integration incident types. ::: - **Mapper (Incoming)** — a name of the integration mapper for incoming incidents. By default, *Veeam ONE Incoming Mapper* is used. To customize the default mapper, find it on the **Settings** > **Objects Setup** > **Incidents** > **Classification and Mapping** tab, make a copy and edit mapping between event attributes and integration incident types. Then, select the new mapper in the instance settings. - **First Fetch Time** — a time period that defines how far back in time incidents will be fetched from the instance for the first time. The default value is *3 days*. - **Triggered Alarms Per Request** — maximum number of incidents based on triggered alarms that can be created per fetch. The default value is *200*. - **Incidents Fetch Interval** — a time interval for fetching new incidents from the instance. The default value is *10 minutes*. 5. To check the connection to the Veeam ONE REST API, click **Test**. 6. If the check is successful, click **Save & exit**. Fetching incidents will start automatically. ::: tip To view fetch history, select the instance and click the history icon. ::: ![](images/xsoar_vone_instance_add.png)