Comprehensive data protection for all workloads
Post Reply
jround
Enthusiast
Posts: 37
Liked: 6 times
Joined: Jun 04, 2019 3:01 pm
Contact:

Veeam SIEM logs

Post by jround » 1 person likes this post

Does Veeam B&R provide the functionality to export logs to a SIEM system (We have recently implemented Logpoint) other than the basic ones logged under Windows Event Viewer?

We are currently running Veeam v10, not sure if v11 offers anything different
chris.childerhose
Veeam Vanguard
Posts: 636
Liked: 154 times
Joined: Aug 13, 2014 6:03 pm
Full Name: Chris Childerhose
Location: Toronto, ON
Contact:

Re: Veeam SIEM logs

Post by chris.childerhose »

As far as I am aware there is no export option to SIEM or others like that. You can export logs but it is exported to ZIP format for attaching to cases, etc.

Would be very interesting to have this though.
-----------------------
Chris Childerhose
Veeam Vanguard / Veeam Legend / Veeam Ceritified Architect / VMCE
vExpert / VCAP-DCA / VCP8 / MCITP
Personal blog: https://just-virtualization.tech
Twitter: @cchilderhose
HannesK
Product Manager
Posts: 14840
Liked: 3086 times
Joined: Sep 01, 2014 11:46 am
Full Name: Hannes Kasparick
Location: Austria
Contact:

Re: Veeam SIEM logs

Post by HannesK »

Hello,
what software are you using? Does that software have some "log file agent" that can just send everything from c:\programdata\veeam\... to your software? I used filebeat some time ago and would assume that similar options exist "everywhere".

Best regards,
Hannes
chris.childerhose
Veeam Vanguard
Posts: 636
Liked: 154 times
Joined: Aug 13, 2014 6:03 pm
Full Name: Chris Childerhose
Location: Toronto, ON
Contact:

Re: Veeam SIEM logs

Post by chris.childerhose »

That is interesting and will check out that app. Need to find a way to move logs and this might be it.
-----------------------
Chris Childerhose
Veeam Vanguard / Veeam Legend / Veeam Ceritified Architect / VMCE
vExpert / VCAP-DCA / VCP8 / MCITP
Personal blog: https://just-virtualization.tech
Twitter: @cchilderhose
wishr
Veteran
Posts: 3077
Liked: 455 times
Joined: Aug 07, 2018 3:11 pm
Full Name: Fedor Maslov
Contact:

Re: Veeam SIEM logs

Post by wishr » 1 person likes this post

Hi Chris,

Currently, there is no interface allowing you to get a complete security-related data, but this is something we are keeping in mind for the next product versions.

Thanks
chris.childerhose
Veeam Vanguard
Posts: 636
Liked: 154 times
Joined: Aug 13, 2014 6:03 pm
Full Name: Chris Childerhose
Location: Toronto, ON
Contact:

Re: Veeam SIEM logs

Post by chris.childerhose »

That is great to hear. If this app works to get some logs over to a server to analyze that works for me for now. I typically use the log location anyway to look in to when I need.
-----------------------
Chris Childerhose
Veeam Vanguard / Veeam Legend / Veeam Ceritified Architect / VMCE
vExpert / VCAP-DCA / VCP8 / MCITP
Personal blog: https://just-virtualization.tech
Twitter: @cchilderhose
wishr
Veteran
Posts: 3077
Liked: 455 times
Joined: Aug 07, 2018 3:11 pm
Full Name: Fedor Maslov
Contact:

Re: Veeam SIEM logs

Post by wishr »

Chris,

You should be good because as far as I see Logpoint is capable of consuming Windows Event Logs and for us it's a go to interface to providing that type of data.

The solution Hannes mentioned above may also work, but you may need to configure rules and parsing on your own to get security-specific information from the generic text logs. Also, keep in mind that we can change text logs in any version, which may break the existing rules.

Thanks
chris.childerhose
Veeam Vanguard
Posts: 636
Liked: 154 times
Joined: Aug 13, 2014 6:03 pm
Full Name: Chris Childerhose
Location: Toronto, ON
Contact:

Re: Veeam SIEM logs

Post by chris.childerhose »

Thanks. I will look in to Logpoint as well.
-----------------------
Chris Childerhose
Veeam Vanguard / Veeam Legend / Veeam Ceritified Architect / VMCE
vExpert / VCAP-DCA / VCP8 / MCITP
Personal blog: https://just-virtualization.tech
Twitter: @cchilderhose
HangTen
Veeam Legend
Posts: 30
Liked: 1 time
Joined: Jan 21, 2021 3:17 pm
Full Name: Hin Tang
Contact:

Re: Veeam SIEM logs

Post by HangTen »

Hello. I just found this thread and am looking to see if the answers have changed in the past year. Thanks.
Gostev
Chief Product Officer
Posts: 31809
Liked: 7300 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Veeam SIEM logs

Post by Gostev » 2 people like this post

Hello, we're working on adding syslog integration in the next minor release. Thanks!
chris.childerhose
Veeam Vanguard
Posts: 636
Liked: 154 times
Joined: Aug 13, 2014 6:03 pm
Full Name: Chris Childerhose
Location: Toronto, ON
Contact:

Re: Veeam SIEM logs

Post by chris.childerhose »

That is going to be great Gostev. Looking forward to that for sure. :)
-----------------------
Chris Childerhose
Veeam Vanguard / Veeam Legend / Veeam Ceritified Architect / VMCE
vExpert / VCAP-DCA / VCP8 / MCITP
Personal blog: https://just-virtualization.tech
Twitter: @cchilderhose
haarloser
Novice
Posts: 4
Liked: 1 time
Joined: Jun 26, 2020 5:50 am
Full Name: Jan H.
Contact:

Re: Veeam SIEM logs

Post by haarloser »

Gostev wrote: Jul 04, 2023 5:09 pm Hello, we're working on adding syslog integration in the next minor release. Thanks!
Any idea when this will be released?
Kind Regards
Gostev
Chief Product Officer
Posts: 31809
Liked: 7300 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Veeam SIEM logs

Post by Gostev » 1 person likes this post

We plan to ship it before the end of this year.
eeberg
Veeam Software
Posts: 48
Liked: 20 times
Joined: Apr 28, 2020 3:01 pm
Full Name: Eric Ellenberg
Location: Atlanta, GA, USA
Contact:

Re: Veeam SIEM logs

Post by eeberg »

FYI to close the loop: syslog support shipped in 12.1 on December 5, 2023. Details and release notes available in KB4510: Release Information for Veeam Backup & Replication 12.1 and Updates.

Other details are available in a new section of the user guide.
Solutions Architect, Enterprise Applications | Product Management, Alliances | Veeam Software
Post Reply

Who is online

Users browsing this forum: Bing [Bot] and 267 guests