How File System Activity Analysis Works

File system activity analysis is started in the following situations:

  • When the backup job is complete and indexing data is saved on the backup server. For machines, guest file system indexing must be enabled in the backup job, and indexing data is saved in the VBRCatalog folder (for Veeam Backup & Replication on Microsoft Windows) or /var/lib/veeam/catalog/ directory (for Veeam Backup & Replication on Linux).
  • If the Veeam Data Analyzer Service gets new indexing data after the service starts.
  • If you import backups with the Import guest file system index data to the catalog check box selected.

If malware activity is detected, the Veeam Data Analyzer Service creates a malware detection event and marks objects as Suspicious. This can trigger a proactive signature-based scan, if you have it enabled. For more information, see Signature Detection.

Note

If you upgrade to Veeam Backup & Replication 13.1 from versions older than 12.1, old indexing data will not be scanned.

If you disable file system activity analysis for a period of time and enable it again, indexing data created during this time will be scanned in the following cases:

  • When the next backup job is complete.
  • When the Veeam Data Analyzer Service restarts.

Note that this process may increase the load on the backup server, depending on the size of the indexing data.

Page updated 2026-08-11

Page content applies to build 13.1.1.18