- About Veeam Backup & Replication REST API
- Overview
- How To
- Changelog
- Login
- License
- postInstall License
- getGet Installed License
- postRemove License
- postCreate License Usage Report
- postRenew Installed License
- getGet Consumption of Socket Licenses
- postRevoke Socket License
- getGet Instance Licenses Consumption
- postAssign Instance License
- postRevoke Instance License
- getGet Capacity License Consumption
- postRevoke Capacity License From Unstructured Data Workload
- postUpdate License
- postEnable or Disable License Auto Update
- postEnable or Disable Instance Consumption for Unlicensed Agents
- Credentials
- getGet All Credentials
- postAdd Credentials Record
- getGet Credentials Record
- putEdit Credentials Record
- delRemove Credentials Record
- postChange Password
- postChange Linux Private Key
- postChange Linux Root Password
- getGet All Cloud Credentials
- postAdd Cloud Credentials Record
- postGet Microsoft Entra ID Verification Code
- postRegister Microsoft Entra ID Application
- postGet Google Authentication Information
- getGet Cloud Credentials Record
- putEdit Cloud Credentials Record
- delRemove Cloud Credentials Record
- postChange Secret Key
- postChange Google Service Account
- postChange Certificate
- getGet All Helper Appliances
- postAdd or Edit Helper Appliance
- getGet Helper Appliance
- delRemove Helper Appliance
- Encryption
- Service
- Services
- Connection
- Cloud Browser
- Inventory Browser
- getGet All VMware vSphere Servers
- getGet VMware vSphere Server Objects
- postGet All Servers
- postGet Inventory Objects
- postRescan Inventory Objects
- getGet All Unstructured Data Servers
- getGet Unstructured Data Servers
- getGet All Microsoft Entra ID Tenants
- postAdd Microsoft Entra ID Tenant
- getGet Microsoft Entra ID Tenant
- putEdit Microsoft Entra ID Tenant
- delRemove Microsoft Entra ID Tenant
- Traffic Rules
- General Options
- Security
- postStart Security & Compliance Analyzer
- getGet Security & Compliance Analyzer Last Run
- getGet Security & Compliance Analyzer Schedule
- putModify Security & Compliance Analyzer Schedule
- postReset All Security & Compliance Analyzer Statuses
- getGet Security & Compliance Analyzer Results
- postSuppress Security & Compliance Analyzer Best Practice Status
- postReset Security & Compliance Analyzer Status
- getGet All Authorization Events
- getGet Authorization Event
- Malware Detection
- Configuration Backup
- Managed Servers
- Repositories
- getGet All Repositories
- postAdd Repository
- getGet All Repository States
- getGet Repository
- putEdit Repository
- delRemove Repository
- getGet All Scale-Out Backup Repositories
- postAdd Scale-Out Backup Repository
- getGet Scale-Out Backup Repository
- putEdit Scale-Out Backup Repository
- delRemove Scale-Out Backup Repository
- postEnable Sealed Mode
- postDisable Sealed Mode
- postEnable Maintenance Mode
- postDisable Maintenance Mode
- Proxies
- WAN Accelerators
- Jobs
- Backups
- Backup Objects
- Restore Points
- Backup Browsers
- getGet All File Restore Mount Points
- getGet File Restore Mount Point
- postBrowse File System
- postCompare Attributes
- postCompare Files and Folders
- postSearch for Files and Folders
- postBrowse Search Results
- postRestore Files and Folders to Original Location
- postRestore Files and Folders to Another Location
- postPrepare Files and Folders for Download
- postDownload Files and Folders
- getGet All Unstructured Data Mount Points
- getGet Unstructured Data Mount Point
- postBrowse Unstructured Data File System
- postSearch for Files and Folders in Unstructured Data Source
- postBrowse Search Results
- postCopy Files and Folders to Specific Folder
- getGet Mount Points of All Entra ID Tenants
- getGet Mount Point of Microsoft Entra ID Tenant
- postGet Restore Points of Microsoft Entra ID Tenant
- postGet Microsoft Entra ID Items
- postGet Microsoft Entra ID Item
- postGet Restore Points of Microsoft Entra ID Item
- postValidate Microsoft Entra ID Items
- postCheck Microsoft Entra ID Items in Production
- postGenerate Microsoft Entra ID User Passwords
- postRestore Microsoft Entra ID Items
- postRestore Microsoft Entra ID Item Properties
- postCompare Microsoft Entra ID Item Properties
- postStart Comparing Microsoft Entra ID Item Properties
- getGet Comparison Results for Microsoft Entra ID Items
- postExport Microsoft Entra ID Items
- postUpload Microsoft Entra ID Users
- postUpload Microsoft Entra ID Groups
- postUpload Microsoft Entra ID Administrative Units
- postUpload Microsoft Entra ID Roles
- postUpload Microsoft Entra ID Applications
- getGet All Restore Sessions of Microsoft Entra ID Tenant
- getGet Restore Session of Microsoft Entra ID Tenant
- getGet Restore Session Logs of Microsoft Entra ID Tenant
- postStop Restore Session of Microsoft Entra ID Tenant
- Restore
- getGet All VM Mount Points
- postStart Instant Recovery
- getGet VM Mount Point
- postStop VM Publishing
- postStart VM Migration
- postRestore Entire VMware vSphere VM
- postRestore Entire VMware Cloud Director VM
- getGet All FCD Mounts
- postStart Instant FCD Recovery
- getGet FCD Mount Point
- postStop FCD Publishing
- postStart FCD Migration
- postStart File Restore
- postUnmount File System
- postGet User Code for Delegated Restore of Microsoft Entra ID Items
- postGet Credentials for Delegated Restore of Microsoft Entra ID Items
- postMount Microsoft Entra ID Tenant
- postUnmount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Audit Log Restore
- postUnmount Microsoft Entra ID Audit Logs
- Data Integration API
- Tasks
- Replicas
- Replica Restore Points
- Failover
- Failback
- Sessions
- Agents
- Automation
- postImport Jobs
- postExport Jobs
- postImport Credentials
- postExport Credentials
- postImport Cloud Credentials
- postExport Cloud Credentials
- postImport Proxies
- postExport Proxies
- postImport Servers
- postExport Servers
- postImport Repositories
- postExport Repositories
- postImport Encryption Passwords
- postExport Encryption Passwords
- getGet All Automation Sessions
- getGet Automation Session
- getGet Automation Session Logs
- postStop Automation Session
The Malware Detection section defines paths and operations for managing malware events and scanning backups with antivirus software or YARA rules.
Get All Malware Events
The HTTP GET request to the /api/v1/malwareDetection/events
path allows you to get an array of all malware events created on the backup server.
Available to: Veeam Backup Administrator, Incident API Operator.
query Parameters
skip | integer <int32> Number of events to skip. |
limit | integer <int32> Maximum number of events to return. |
orderColumn | string (ESuspiciousActivityEventsFiltersOrderColumn) Sorts events by one of the event parameters. |
orderAsc | boolean If |
typeFilter | string (ESuspiciousActivityType) Filters events by event type. |
detectedAfterTimeUtcFilter | string <date-time> Returns events created after the specified time, in UTC. |
detectedBeforeTimeUtcFilter | string <date-time> Returns events created before the specified time, in UTC. |
backupObjectIdFilter | string <uuid> Filters events by backup object ID. |
stateFilter | string (ESuspiciousActivityState) Filters events by state. |
sourceFilter | string (ESuspiciousActivitySourceType) Filters events by source type. |
severityFilter | string (ESuspiciousActivitySeverity) Filters events by severity. |
createdByFilter | string Filters events by the |
engineFilter | string Filters events by the |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "type": "Unknown",
- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "displayName": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a"
}, - "state": "Created",
- "details": "string",
- "source": "Manual",
- "severity": "Clean",
- "createdBy": "string",
- "engine": "string"
}
], - "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 0
}
}
Create Malware Event
The HTTP POST request to the /api/v1/malwareDetection/events
path allows you to create a new malware event.
Available to: Veeam Backup Administrator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
detectionTimeUtc required | string <date-time> Detection date and time, in UTC. |
required | object (SuspiciousActivityMachineSpec) Machine that you want to mark with the malware event. Specify at least 2 parameters. Note that Veeam Backup & Replication can identify a machine by its FQDN, IPv4 address and IPv6 address only if the machine has been powered on during the backup. If you back up a powered-off machine, Veeam Backup & Replication will not get the machine IP addresses and domain name and will not be able to identify the machine. |
details required | string Event description. |
engine required | string Detection engine. |
Malware event has been created.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "fqdn": "string",
- "ipv4": "string",
- "ipv6": "string",
- "uuid": "string"
}, - "details": "string",
- "engine": "string"
}
- 201
- 400
- 401
- 403
- 500
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "type": "Unknown",
- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "displayName": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a"
}, - "state": "Created",
- "details": "string",
- "source": "Manual",
- "severity": "Clean",
- "createdBy": "string",
- "engine": "string"
}
], - "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 0
}
}
Get Malware Event
The HTTP GET request to the /api/v1/malwareDetection/events/{id}
path allows you to get a malware event that has the specified id
.
Available to: Veeam Backup Administrator, Incident API Operator.
path Parameters
id required | string <uuid> ID of the event. |
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "type": "Unknown",
- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "displayName": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a"
}, - "state": "Created",
- "details": "string",
- "source": "Manual",
- "severity": "Clean",
- "createdBy": "string",
- "engine": "string"
}
Get YARA Rules
The HTTP GET request to the /api/v1/malwareDetection/yaraRules
path allows you to get YARA rules located in the Veeam Backup & Replication installation folder. The default path is %ProgramFiles%\Veeam\Backup and Replication\Backup\YaraRules.
Available to: Veeam Backup Administrator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "data": [
- {
- "fileName": "FindFileByHash.yara"
}, - {
- "fileName": "FindFileByParameters.yara"
}, - {
- "fileName": "FindString.yara"
}
], - "pagination": {
- "total": 3,
- "count": 3,
- "skip": 0,
- "limit": 3
}
}
Scan Backups with Antivirus or YARA Rules
The HTTP POST request to the /api/v1/malwareDetection/scanBackup
allows you to scan backups with antivirus or YARA rules.
Available to: Veeam Backup Administrator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.2-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
required | Array of objects (BackupObjectPair) Array of objects containing the backup IDs and backup object IDs. | ||||||||
scanMode required | string (EMalwareBackupScanMode) Backup scan mode.
| ||||||||
required | object (MalwareBackupScanSpecEngine) Type of backup scan engine. | ||||||||
object (MalwareBackupScanRange) Backup scan range. If you do not specify this parameter, Veeam Backup & Replication will scan all available restore points. | |||||||||
continueScan | boolean If |
A SureBackup
session has been created to scan the backup. To check the progress, track the session state
.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "backupObjectPair": [
- {
- "backupId": "ffcedddf-577d-4033-aab8-9c6f46c82b8d",
- "backupObjectId": "67785a3a-dd33-4f33-9869-111ece902f9b"
}
], - "scanMode": "AllInInterval",
- "scanEngine": {
- "useAntivirusEngine": "false",
- "useYaraRule": "true",
- "yaraRule": {
- "fileName": "FindFileByHash.yara"
}
}
}
- 201
- 400
- 401
- 403
- 500
{- "sessionType": "SureBackup",
- "state": "Starting",
- "platformName": null,
- "id": "a330c612-07b2-4c3a-adbf-0007f904bbfd",
- "name": "Scan Backup",
- "jobId": "34b77de9-d5e2-4752-aff8-929bc428e80f",
- "creationTime": "2024-11-11T12:34:46.027793",
- "endTime": null,
- "progressPercent": 0,
- "result": null,
- "resourceId": null,
- "resourceReference": null,
- "parentSessionId": null,
- "usn": 0,
- "platformId": null
}