Veeam Data Cloud Integrations

Veeam Data Cloud integrations forward security, audit and operational events from your Veeam Data Cloud organization to external SIEM, observability and automation platforms. Streaming events to 3rd party tools helps you correlate Veeam Data Cloud activity with the rest of your environment, automate incident response and meet audit and compliance requirements.

Integration management in Veeam Data Cloud is available to users with the OrganizationAdmin role assigned.

Veeam Data Cloud supports the following integration types:

  • Splunk — forwards events to a Splunk instance over the HTTP Event Collector (HEC).
  • CrowdStrike — forwards events to CrowdStrike LogScale using an ingest token or CrowdStrike Next-Gen SIEM using an API token.
  • Generic Webhook — sends events to any HTTP endpoint with a custom method, authentication headers and additional HTTP headers.

For each integration, you can customize the message format and define event rules to filter the events that are forwarded. If you do not define any event rules, Veeam Data Cloud forwards raw events.

For the list of supported events, see the Veeam Data Cloud Event Reference.

Before You Begin

Before you configure an integration to forward events from Veeam Data Cloud, consider the following:

  • Veeam Data Cloud does not guarantee that events arrive in the order in which they occurred. To restore the original order, sort events by the timestamp field.
  • Events normally reach the destination platform within seconds. Under high load, delivery can take longer. To establish when an event actually occurred, use the timestamp field of the event, not the time when the event arrived in the destination platform.
  • Veeam Data Cloud uses at-least-once delivery, so the same event can arrive more than once. Duplicates occur when the destination platform receives an event but the delivery confirmation does not reach Veeam Data Cloud, for example, because of a network problem. In this case, Veeam Data Cloud sends the event again. To process each event only once, deduplicate events by the event ID field.
  • If the destination platform is unreachable, times out or returns a server error, Veeam Data Cloud retries delivery automatically with progressively longer intervals for up to one hour. As a result, short outages on the destination side do not lead to data loss.

If an outage in the destination lasts longer than one hour, Veeam Data Cloud stops the retries and drops the remaining events.

  • If the destination platform rejects the request, for example, because of an incorrect URL, invalid credentials or a certificate that is expired or untrusted, Veeam Data Cloud stops delivery immediately instead of retrying and marks the integration as unhealthy. All events that occur while the integration is unhealthy are lost.

The integration does not recover automatically. You must fix the issue on the destination side and then reset the integration status manually. For more information, see Viewing Integration Details.

In This Section