- About Veeam Backup & Replication REST API
- Overview
- How To
- Changelog
- Login
- Service
- Services
- Credentials
- getGet All Credentials
- postAdd Credentials Record
- getGet Credentials Record
- putEdit Credentials Record
- delRemove Credentials Record
- postChange Password
- postChange Linux Private Key
- postChange Linux Root Password
- getGet All Cloud Credentials
- postAdd Cloud Credentials Record
- postGet Microsoft Entra ID Verification Code
- postRegister Microsoft Entra ID Application
- postGet Google Authentication Information
- getGet Cloud Credentials Record
- putEdit Cloud Credentials Record
- delRemove Cloud Credentials Record
- postChange Secret Key
- postChange Google Service Account
- postChange Certificate
- getGet All Helper Appliances
- postAdd or Edit Helper Appliance
- getGet Helper Appliance
- delRemove Helper Appliance
- Encryption
- getGet All Encryption Passwords
- postAdd Encryption Password
- getGet Encryption Password
- putEdit Encryption Password Hint
- delRemove Encryption Password
- postChange Encryption Password
- postVerify Encryption Password
- getGet All KMS Servers
- postAdd KMS Server
- getGet KMS Server
- putEdit KMS Server
- delRemove KMS Server
- postChange KMS Server Certificate
- License
- postInstall License
- getGet Installed License
- postRemove License
- postCreate License Usage Report
- postRenew Installed License
- getGet Consumption of Socket Licenses
- postRevoke Socket License
- getGet Instance Licenses Consumption
- postAssign Instance License
- postRevoke Instance License
- postRemove Instance License
- getGet Capacity License Consumption
- postRevoke Capacity License From Unstructured Data Workload
- postUpdate License
- postEnable or Disable License Auto Update
- postEnable or Disable Instance Consumption for Unlicensed Agents
- Connection
- Cloud Browser
- Inventory Browser
- getGet All VMware vSphere Servers
- getGet VMware vSphere Server Objects
- postRescan Inventory Objects
- postGet All Servers
- postGet Inventory Objects
- postGet All Protection Groups
- postGet Inventory Objects for Specific Protection Group
- getGet All Unstructured Data Servers
- getGet Unstructured Data Servers
- getGet All Microsoft Entra ID Tenants
- postAdd Microsoft Entra ID Tenant
- getGet Microsoft Entra ID Tenant
- putEdit Microsoft Entra ID Tenant
- delRemove Microsoft Entra ID Tenant
- getGet Active Directory Objects from Domain
- Traffic Rules
- General Options
- Global Exclusions
- Security
- postStart Security & Compliance Analyzer
- getGet Security & Compliance Analyzer Last Run
- getGet Security & Compliance Analyzer Schedule
- putModify Security & Compliance Analyzer Schedule
- postReset All Security & Compliance Analyzer Statuses
- getGet Security & Compliance Analyzer Results
- postSuppress Security & Compliance Analyzer Best Practice Status
- postReset Security & Compliance Analyzer Status
- getGet All Authorization Events
- getGet Authorization Event
- Malware Detection
- Configuration Backup
- Deployment
- Managed Servers
- getGet All Servers
- postAdd Server
- postGet vCenter Servers Attached to Cloud Director Server
- postGet Hyper-V Servers Managed by Hyper-V Cluster or SCVMM Server
- getGet Server
- putEdit Server
- delRemove Server
- postChange to Single-Use Credentials
- getGet Volumes for Hyper-V Standalone Server
- putEdit Volumes on Hyper-V Standalone Server
- postRescan All Managed Servers
- postRescan Managed Server
- getDefault Set of Optional Managed Server Components
- postUpdate Managed Server Components
- Repositories
- getGet All Repositories
- postAdd Repository
- postRescan Repositories
- getGet All Repository States
- getGet Repository
- putEdit Repository
- delRemove Repository
- getGet All Scale-Out Backup Repositories
- postAdd Scale-Out Backup Repository
- getGet Scale-Out Backup Repository
- putEdit Scale-Out Backup Repository
- delRemove Scale-Out Backup Repository
- postEnable Sealed Mode
- postDisable Sealed Mode
- postEnable Maintenance Mode
- postDisable Maintenance Mode
- Mount Servers
- Proxies
- WAN Accelerators
- Jobs
- Backups
- Backup Objects
- Restore Points
- Restore
- getGet All Instant Recovery Mount Points of VMware vSphere VMs
- postStart Instant Recovery of VMware vSphere VM
- getGet Instant Recovery Mount Point of VMware vSphere VM
- postStop Publishing VMware vSphere VM
- postStart Migrating VMware vSphere VM
- getGet All Instant Recovery Mount Points of Microsoft Hyper-V VMs
- postStart Instant Recovery of Microsoft Hyper-V VM
- getGet Instant Recovery Mount Point of Microsoft Hyper-V VM
- postStop Publishing Microsoft Hyper-V VM
- postStart Migrating Microsoft Hyper-V VM
- getGet All Mount Points for Instant Recovery to Azure
- postStart Instant Recovery to Azure
- getGet Mount Point for Instant Recovery to Azure
- getGet All Mount Sessions for Instant Recovery to Azure
- postStop Publishing Machine to Azure
- postStart Migrating Machine to Azure
- getGet Settings for Switchover to Azure
- putUpdate Settings for Switchover to Azure
- postStart Switchover to Azure
- postRestore Entire VMware vSphere VM
- postRestore Entire VMware Cloud Director VM
- postRestore Entire Microsoft Hyper-V VM
- getGet All FCD Mount Points
- postStart Instant FCD Recovery
- getGet FCD Mount Point
- postStop FCD Publishing
- postStart FCD Migration
- postStart File Restore
- postUnmount File System
- postGet User Code for Delegated Restore of Microsoft Entra ID Items
- postGet Credentials for Delegated Restore of Microsoft Entra ID Items
- postMount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Tenant Restore from Copy
- postUnmount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Audit Log Restore
- postUnmount Microsoft Entra ID Audit Logs
- Data Integration API
- Backup Browsers
- postValidate Target Machine Credentials
- getGet All File Restore Mount Points
- getGet File Restore Mount Point
- getGet Restored Files Audit
- postBrowse File System
- postCompare Attributes
- postCompare Files and Folders
- postSearch for Files and Folders
- postBrowse Search Results
- postRestore Files and Folders to Original Location
- postRestore Files and Folders to Another Location
- postPrepare Files and Folders for Download
- postDownload Files and Folders
- getGet All Unstructured Data Mount Points
- getGet Unstructured Data Mount Point
- postBrowse Unstructured Data File System
- postSearch for Files and Folders in Unstructured Data Source
- postBrowse Search Results
- postCopy Files and Folders to Specific Folder
- getGet Mount Points of All Entra ID Tenants
- getGet Mount Point of Microsoft Entra ID Tenant
- postGet Restore Points of Microsoft Entra ID Tenant
- getGet Protection Scope of Microsoft Entra ID Tenant
- postGet Microsoft Entra ID Items
- postGet Microsoft Entra ID Item
- postGet Restore Points of Microsoft Entra ID Item
- postValidate Microsoft Entra ID Items
- postCheck Microsoft Entra ID Items in Production
- postGenerate Microsoft Entra ID User Passwords
- postRestore Microsoft Entra ID Items
- postRestore Microsoft Entra ID Item Properties
- postCompare Microsoft Entra ID Item Properties
- postStart Comparing Microsoft Entra ID Item Properties
- getGet Comparison Results for Microsoft Entra ID Items
- postStart Comparing Microsoft Entra ID Conditional Access Policy
- getGet Comparison Results for Microsoft Entra ID Conditional Access Policy
- postExport Microsoft Entra ID Items
- postUpload Microsoft Entra ID Users
- postUpload Microsoft Entra ID Groups
- postUpload Microsoft Entra ID Administrative Units
- postUpload Microsoft Entra ID Roles
- postUpload Microsoft Entra ID Applications
- postUpload Microsoft Entra ID Conditional Access Policies
- getGet All Restore Sessions of Microsoft Entra ID Tenant
- getGet Restore Session of Microsoft Entra ID Tenant
- getGet Restore Session Logs of Microsoft Entra ID Tenant
- postStop Restore Session of Microsoft Entra ID Tenant
- Tasks
- Replicas
- Replica Restore Points
- Failover
- Failback
- Sessions
- Agents
- getGet All Recovery Tokens
- postCreate Recovery Token
- getGet Recovery Token
- putEdit Recovery Token
- delDelete Recovery Token
- getGet All Protected Computers
- getGet Protected Computer
- getGet Discovered Entities
- postRescan Discovered Entities
- postInstall Agent on Discovered Entities
- postUninstall Agent from Discovered Entities
- postUninstall All Components from Discovered Entities
- getGet Discovered Entity
- delRemove Discovered Entity
- getGet Linux Agent Packages
- getGet Unix Agent Packages
- Protection Groups
- Active Directory Domains
- Automation
- postImport Jobs
- postExport Jobs
- postImport Credentials
- postExport Credentials
- postImport Cloud Credentials
- postExport Cloud Credentials
- postImport Proxies
- postExport Proxies
- postImport Servers
- postExport Servers
- postImport Repositories
- postExport Repositories
- postImport Encryption Passwords
- postExport Encryption Passwords
- getGet All Automation Sessions
- getGet Automation Session
- getGet Automation Session Logs
- postStop Automation Session
- Log export
The Malware Detection section defines paths and operations for managing malware events and scanning backups with antivirus software or YARA rules.
Get All Malware Events
The HTTP GET request to the /api/v1/malwareDetection/events
path allows you to get an array of all malware events created on the backup server.
Available to: Veeam Backup Administrator, Incident API Operator.
query Parameters
skip | integer <int32> Number of events to skip. |
limit | integer <int32> Default: 200 Maximum number of events to return. |
orderColumn | string (ESuspiciousActivityEventsFiltersOrderColumn) Sorts events by one of the event parameters. |
orderAsc | boolean If |
typeFilter | Array of strings (ESuspiciousActivityType) Filters events by event type. |
detectedAfterTimeUtcFilter | string <date-time> Returns events created after the specified time, in UTC. |
detectedBeforeTimeUtcFilter | string <date-time> Returns events created before the specified time, in UTC. |
backupObjectIdFilter | string <uuid> Filters events by backup object ID. |
stateFilter | Array of strings (ESuspiciousActivityState) Filters events by state. |
sourceFilter | Array of strings (ESuspiciousActivitySourceType) Filters events by source type. |
severityFilter | Array of strings (ESuspiciousActivitySeverity) Filters events by severity. |
createdByFilter | string Filters events by the |
engineFilter | string Filters events by the |
machineNameFilter | string Filters events by the |
header Parameters
x-api-version required | string Default: 1.3-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "type": "Unknown",
- "creationTimeUtc": "2019-08-24T14:15:22Z",
- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "displayName": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - "state": "Created",
- "details": "string",
- "source": "Manual",
- "severity": "Clean",
- "createdBy": "string",
- "engine": "string"
}
], - "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 0
}
}
Create Malware Event
The HTTP POST request to the /api/v1/malwareDetection/events
path allows you to create a new malware event.
Available to: Veeam Backup Administrator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.3-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
detectionTimeUtc required | string <date-time> Detection date and time, in UTC. |
required | object (SuspiciousActivityMachineSpec) Machine that you want to mark with the malware event. Specify at least 2 parameters. Note that Veeam Backup & Replication can identify a machine by its FQDN, IPv4 address and IPv6 address only if the machine has been powered on during the backup. If you back up a powered-off machine, Veeam Backup & Replication will not get the machine IP addresses and domain name and will not be able to identify the machine. |
details required | string Event description. |
engine required | string Detection engine. |
severity | string (ECreatingSuspiciousActivitySeverity) Default: "Infected" Malware status enum for creating suspicious activity operation. |
Malware event has been created.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "fqdn": "string",
- "ipv4": "string",
- "ipv6": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - "details": "string",
- "engine": "string",
- "severity": "Infected"
}
- 201
- 400
- 401
- 403
- 500
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "type": "Unknown",
- "creationTimeUtc": "2019-08-24T14:15:22Z",
- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "displayName": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - "state": "Created",
- "details": "string",
- "source": "Manual",
- "severity": "Clean",
- "createdBy": "string",
- "engine": "string"
}
], - "pagination": {
- "total": 0,
- "count": 0,
- "skip": 0,
- "limit": 0
}
}
Get Malware Event
The HTTP GET request to the /api/v1/malwareDetection/events/{id}
path allows you to get a malware event that has the specified id
.
Available to: Veeam Backup Administrator, Incident API Operator.
path Parameters
id required | string <uuid> Event ID. To get the ID, run the Get All Malware Events request. |
header Parameters
x-api-version required | string Default: 1.3-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "type": "Unknown",
- "creationTimeUtc": "2019-08-24T14:15:22Z",
- "detectionTimeUtc": "2019-08-24T14:15:22Z",
- "machine": {
- "displayName": "string",
- "uuid": "string",
- "backupObjectId": "e5daa78c-c0bb-44d5-8a9c-04130e3d324a",
- "restorePointId": "8c843d10-6d0f-4abe-b898-e1ba18b94f68"
}, - "state": "Created",
- "details": "string",
- "source": "Manual",
- "severity": "Clean",
- "createdBy": "string",
- "engine": "string"
}
Mark Infected Objects as Clean
The HTTP POST request to the /api/v1/malwareDetection/backupObjects/markAsClean
path allows you to mark infected objects as clean.
Available to: Veeam Backup Administrator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.3-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
objectIds required | Array of strings <uuid> Array of backup object IDs to be marked as clean. |
reason required | string Reason why the backup objects are marked as clean. |
markRestorePointsAsClean | boolean If |
excludeFromDetection | boolean If |
noteForExclusion | string Note for exclusion from detection. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "BackupObjectMarkAsCleanSpecExample": {
- "$ref": "#/components/examples/BackupObjectMarkAsCleanSpecExample"
}
}
- 200
- 400
- 401
- 403
- 500
{ }
Get YARA Rules
The HTTP GET request to the /api/v1/malwareDetection/yaraRules
path allows you to get YARA rules located in the Veeam Backup & Replication installation folder. The default path is %ProgramFiles%\Veeam\Backup and Replication\Backup\YaraRules.
Available to: Veeam Backup Administrator, Veeam Restore Operator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.3-rev0 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "data": [
- {
- "fileName": "FindFileByHash.yara"
}, - {
- "fileName": "FindFileByParameters.yara"
}, - {
- "fileName": "FindString.yara"
}
], - "pagination": {
- "total": 3,
- "count": 3,
- "skip": 0,
- "limit": 3
}
}
Scan Backups with Antivirus or YARA Rules
The HTTP POST request to the /api/v1/malwareDetection/scanBackup
allows you to scan backups with antivirus or YARA rules.
Available to: Veeam Backup Administrator, Incident API Operator.
header Parameters
x-api-version required | string Default: 1.3-rev0 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
required | Array of objects (BackupObjectPair) Array of objects containing the backup IDs and backup object IDs. | ||||||||
scanMode required | string (EMalwareBackupScanMode) Backup scan mode.
| ||||||||
required | object (MalwareBackupScanSpecEngine) Type of backup scan engine. | ||||||||
object (MalwareBackupScanRange) Backup scan range. If you do not specify this parameter, Veeam Backup & Replication will scan all available restore points. | |||||||||
continueScan | boolean If |
A SureBackup
session has been created to scan the backup. To check the progress, track the session state
.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "backupObjectPair": [
- {
- "backupId": "ffcedddf-577d-4033-aab8-9c6f46c82b8d",
- "backupObjectId": "67785a3a-dd33-4f33-9869-111ece902f9b"
}
], - "scanMode": "AllInInterval",
- "scanEngine": {
- "useAntivirusEngine": "false",
- "useYaraRule": "true",
- "yaraRule": {
- "fileName": "FindFileByHash.yara"
}
}
}
- 201
- 400
- 401
- 403
- 500
{- "sessionType": "SureBackup",
- "state": "Starting",
- "platformName": null,
- "id": "a330c612-07b2-4c3a-adbf-0007f904bbfd",
- "name": "Scan Backup",
- "jobId": "34b77de9-d5e2-4752-aff8-929bc428e80f",
- "creationTime": "2024-11-11T12:34:46.027793",
- "endTime": null,
- "progressPercent": 0,
- "result": null,
- "resourceId": null,
- "resourceReference": null,
- "parentSessionId": null,
- "usn": 0,
- "platformId": null
}