Comprehensive data protection for all workloads
Post Reply
crackocain
Service Provider
Posts: 255
Liked: 28 times
Joined: Dec 14, 2015 8:20 pm
Full Name: Mehmet Istanbullu
Location: Türkiye
Contact:

Feature Request - Split Indexing and Malware Detection

Post by crackocain »

Hi

We want to use malware detection for all virtual machine but indexing is not necessary. For as i know right now it's mutual. Is there any plan to split or how we use like this right now.
VMCA v12
david.domask
Veeam Software
Posts: 2838
Liked: 650 times
Joined: Jun 28, 2016 12:12 pm
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by david.domask »

Hi Mehmet,

Thank you for the request -- just to confirm, you're talking about the Guest Indexing Scan? You'd like this separated from the Guest Indexing?/

If you're discussing just the inline scan, please see how to enable it here: https://helpcenter.veeam.com/docs/backu ... ml?ver=120 It's a separate detection method, and can be run without indexing enabled.

Can you clarify if this meets your needs? Similarly, what's the main concern with using indexing?
David Domask | Product Management: Principal Analyst
crackocain
Service Provider
Posts: 255
Liked: 28 times
Joined: Dec 14, 2015 8:20 pm
Full Name: Mehmet Istanbullu
Location: Türkiye
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by crackocain »

Hello David

File Detection works only indexing enabled. Some attacks can only be detected this way. We had an incident last week where Veeam was able to detect the malware after we turned on this feature. Another problem is that the indexing feature does not automatically include the Windows and Program Files folders. Because indexing is to find the searched file quickly. However, viruses target these folders. There is a contradiction here too.
VMCA v12
david.domask
Veeam Software
Posts: 2838
Liked: 650 times
Joined: Jun 28, 2016 12:12 pm
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by david.domask »

Hi Mehmet,

Thanks for the response -- indeed, it's important to clarify which malware detection feature you're discussion, as inline scan works independently of the Guest Indexing scan and they have different purposes.

Indexing scan works by using the guest index to scan for known malicious file types as well as several other indicators of compromise. The Indicators of Compromise feature (v12.3 and newer) has additional checks. Both of these require the Guest Indexing to be enabled. While you are correct that the indexing does not scan some common windows directories by default, based on how it works (looking for specific file extensions and other indicators of compromise), this is expected as it's not performing an AV scan on these directories, it's looking for specific artifacts (read: extensions, evidence of compromise like specific files/folders, etc) that would indicate there is/was a compromise. So while I do understand your point, Malware Detection is best combined with regular AV scans (either through Veeam with Veeam Threat Hunter (or any supported AV), or a normal AV scan on the OS itself)

So I would ask again if you can elaborate on why separating Guest Indexing is preferable here -- I'm just not quite sure I understand the benefit.
David Domask | Product Management: Principal Analyst
crackocain
Service Provider
Posts: 255
Liked: 28 times
Joined: Dec 14, 2015 8:20 pm
Full Name: Mehmet Istanbullu
Location: Türkiye
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by crackocain »

"When the backup job with guest file system indexing enabled is complete and indexing data is saved in the VBRCatalog folder on the backup server."
https://helpcenter.veeam.com/docs/backu ... ml?ver=120

Indexing data will grow a lot. Normally, the need for indexing data is only for finding the file that is being searched. In this case, there is actually no situation to be found later. Therefore, there is no need to keep this data on the VBR server and inflate it.

As I mentioned before, these scans need to be done in all directories. Indexing excludes default folders. This is again a situation that can be solved manually. Not really a problem.
VMCA v12
Gostev
Chief Product Officer
Posts: 32374
Liked: 7727 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by Gostev »

Starting from 12.3 indexing data stored on backup server shouldn't grow a lot and "inflate the VBR server" as it's default retention was reduced to a low number of days sufficient for reliable malware detection.
crackocain
Service Provider
Posts: 255
Liked: 28 times
Joined: Dec 14, 2015 8:20 pm
Full Name: Mehmet Istanbullu
Location: Türkiye
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by crackocain »

Great news Anton!
VMCA v12
mkaec
Veteran
Posts: 480
Liked: 143 times
Joined: Jul 16, 2015 1:31 pm
Full Name: Marc K
Contact:

Re: Feature Request - Split Indexing and Malware Detection

Post by mkaec »

Is indexing still using the glacially slow enumeration algorithm?
Post Reply

Who is online

Users browsing this forum: Google [Bot], Semrush [Bot] and 16 guests