Objective
Veeam is a data protection and disaster recovery solution designed for modern IT environments. ManageEngine EventLog Analyzer offers Veeam extension for which is designed to enable seamless integration of log data from Veeam Backup & Replication or Veeam ONE into the ManageEngine EventLog Analyzer/Log360 ecosystem. This extension provides features such as log collection, parsing, dashboard widgets, reporting, alerting, correlation, and advanced log search capabilities. This article offers step by step instructions to enable the auditing by adding Veeam.
Prerequisites
Steps to follow
Complete configuration of Veeam in EventLog Analyzer has to be done with three stage of configuration.
Download and Enable Extension for Veeam
Onboard Veeam in EventLog Analyzer
Enable Rules for Veeam monitoring
Enable Alerts for Veeam Alerting
I. Download and Enable Extension for Veeam:
Open EventLog Analyzer User Interface and navigate to Settings >> Admin Settings >> Installed Extensions >> Install Extension.
Choose Browse button, browse the downloaded file and upload it to install or update the extension.
Choose Continue to Install.
By default, all the provided capabilities of this plugin will be enabled if you would like to customize them, choose Customize.
Choose Continue to Install.
Once the extension is installed, EventLog Analyzer is now equipped with capabilities to monitor and detect Veeam log source.
II. Onboard Veeam in EventLog Analyzer:
1. After configuring the log source, navigate to Settings > Marketplace > Installed Extensions. Click Manage under configuration to open the Manage Configuration page. Choose "Configure" under Manage Configuration.
You can also navigate to Settings >> Log Source Configuration >> Applications >> Other Applications
2. Choose Veeam, pick the log source and select Add.
3. Now, you need to enable Event Forwarding, in either Veeam ONE or Veeam Backup & Replication to send events to EventLog Analyzer. This requires a Veeam Data Platform Advanced or Premium license that supports syslog event forwarding.
5. Follow the below steps for syslog forwarding.
NOTE: The Syslog forwarding has to be done over the application listened ports. Ensure that the same port is allowed in Application installed server's firewall or any network Firewall in-between. The traffic flows from Veeam to EventLog Analyzer installed server.
Event forwarding in Veeam ONE
Open Veeam ONE Client and navigate to Server Settings > Syslog.
Check Enable Syslog.
In Syslog server, enter the Hostname or IP of the EventLog Analyzer server in the log source.
Select mail under the Syslog facility dropdown.
Choose UDP or TCP under the Syslog transport dropdown.
Enter a port in which the EventLog Analyzer server is listening for Syslogs.
Check all options under Syslog audit events to enable comprehensive search and reporting in EventLog Analyzer.
Click OK to save the configuration.
Event forwarding in Veeam Backup & Replication
Open Veeam Backup & Replication Console and go to Options > Event Forwarding.
Click Add under Syslog servers to configure a Syslog server.
In the Server field, provide the Hostname or IP of the EventLog Analyzer server.
Enter a port in which the EventLog Analyzer server is listening for Syslogs.
Select UDP or TCP under the Transport dropdown.
Click OK to add the syslog server, then click Apply to save changes.
For more details, refer to the official guide on Syslog integration in Veeam Backup & Replication. Once the log packet reached the application, the log collection will start automatically and you will be able to see the events in Reports, Search tab etc.
You can see the Veeam reports under Reports >> Custom Reports catagory.
III. Enable Rules for Veeam monitoring
1. Go to Settings > Marketplace > Installed Extensions. Click Manage under Configuration to open the Manage Configuration page.
2. Click Redirect near Manage Rules.

Case A: For built 13000 and above:
You will be redirected to Security Tab. Search for the Rule name and Select Activate to enable the rules based on the requirement.
Case B: For build versions below 13000:
You will be redirected to Correaltion Tab. Select Veeam from the Rule Category selector to view the available correlation rules. Review the available correlation rules and enable the required ones.
IV. Enable Alerts for Veeam Alerting
After configuring the log source, navigate to Settings > Marketplace > Installed Extensions. Click Manage under configuration to open the Manage Configuration page.
Click Redirect next to Alert Profiles to navigate to the Alerts tab. Extension alert profiles appear under Custom Alert Profiles. Use the Created By column to identify Veeam alert profiles.
Browse the available alert profiles and enable the required ones.
Tips
Download the extension and add the Veeam device before performing syslog configuration.
Ensure to forward the syslogs to EventLog Analyzer/Log360 or the agent for which you are planning to associate by enabling the required Listener Ports.
EventLog Analyzer/Log360 offers the following auditing capabilities while auditing Veeam.
Authentication and authorization
Identity management
Malware detection
Malware detection configuration changes
Malware detection session completion events
Malware activity detection events
Malware remediation actions
Configuration management
Jobs
Job sessions history
Job configurations
Restore sessions history
Infrastructure management
Licensing
Related Article