Comprehensive data protection for all workloads
Post Reply
mathiasd
Service Provider
Posts: 6
Liked: 2 times
Joined: Jan 30, 2024 11:50 am
Full Name: Mathias D
Contact:

[V13] Feature request - Easier access to Malware Detection logs on VSA

Post by mathiasd » 2 people like this post

As many here, we're testing the waters as MSP with rolling out the V13 VSA.
Currently have it running in production for one customer, where we're running into one minor issue: how am I getting our support staff to access to the malware detection logs?

In the malware detection logs we get the following:
19/10/2025 22:50:41 Warning : Locations of suspicious files can be found on the backup server **vsa hostname** at /var/log/VeeamBackup/Malware_Detection_Logs/suspicious_files_25-10-19.log

On Windows based Veeam hosts, this is as easy as just navigating to the folder via our RMM tool and fetching the file.
On the VSA, this becomes much harder. We want to keep the VSA as a locked down "black box" appliance, with our support staff having no access to SSH, no RMM tools installed on it.
Just access to either the fat client on a Windows host, or the web interface for some quick checks.

Via a running support case we got the feedback that we can extract it via the support log system.
This works fine for me as our internal product expert, to do once in a blue moon to troubleshoot, but I can't expect our support staff to spend 10 minutes to collect the log files, extract them, and then go look for the log file.

As such, I'd like to put forward a feature request to make the malware detection log retrievable from within the Backup & Replication console.
Dima P.
Product Manager
Posts: 15060
Liked: 1912 times
Joined: Feb 04, 2013 2:07 pm
Full Name: Dmitry Popov
Location: Prague
Contact:

Re: [V13] Feature request - Easier access to Malware Detection logs on VSA

Post by Dima P. »

Hello Mathias,

Thank you for the feedback - we’ll note this as an improvement request. In the meantime, you can export the logs using Veeam B&R export log it should include malware detection logs as well. Thank you!
petesteven
Veeam Vanguard
Posts: 65
Liked: 86 times
Joined: May 08, 2018 7:34 am
Full Name: Peter Steffan
Contact:

Re: [V13] Feature request - Easier access to Malware Detection logs on VSA

Post by petesteven » 1 person likes this post

+1

We have the same hurdle with the logs. This should work in a different way than via Export Logs.
Peter Steffan - My Blog: petersvirtualworld.de; VMCE2024, VMCA2024, Veeam Vanguard since 2025, Object First ACES since 2026
DaStivi
Veeam Legend
Posts: 523
Liked: 108 times
Joined: Jun 30, 2015 9:13 am
Full Name: Stephan Lang
Location: Austria
Contact:

Re: [V13] Feature request - Easier access to Malware Detection logs on VSA

Post by DaStivi »

+1

easiest thing would be to see the correct folder structure under the files tab in VBR Console... but for some reason the folder/file-tree there is something different then whats on the filesystem of the vsa itself..
CompKingCanada
Novice
Posts: 4
Liked: never
Joined: Mar 03, 2023 3:21 pm
Full Name: Geoff Larsen
Contact:

Re: [V13] Feature request - Easier access to Malware Detection logs on VSA

Post by CompKingCanada »

+1 here too. It's been over a year now...
mabergerp
Lurker
Posts: 1
Liked: never
Joined: Aug 31, 2026 4:58 pm
Full Name: Peter Berger
Contact:

Re: [V13] Feature request - Easier access to Malware Detection logs on VSA

Post by mabergerp »

+1 also for VBR Linux v13.x appliance:

Why I agree/suggest that Malware Detection needs some love.
Today I have to do all of the following steps just to see "if" I have a malware incident. It should not be this difficult and frankly I rarely even bother to check anymore due to the difficulty involved -- which goes against all best-security-practices:

Open VBR application; login as SSO/MFA; Inventory > Malware Detection > Click on the server's name > Show history > Malware events > find the server > right-click server and click "Details". All this work just to show me the VBR Linux appliance path to the file and potential issue.

Open a browser as "veeamadmin" > Veeam Host Management Console > Remote Access > SSH Server. Turn it on. Logout of the VBR appliance.
Log back into the VBR appliance as "veeamso" find and enter the MFA code > click "Approve. Logout of the appliance as "veeamso".

Open PuTTY as "veeamadmin".
cd /var/log/VeeamBackup/Malware_Detection_logs.
ll to see the files. Compare it to the output of the VBR Application for the server issue.
vi or cat the file above.
Read/review the file to see if it is truly malware or just routine stuff.
Exit SSH
I never bother to disable SSH Server in the VBR appliance as it'll just timeout and stop by itself. I know - not good security practice, but just more steps to do.

Go back into VBR application > Inventory > Malware Detection >Server > Mark as Clean. Provide a description as to why it was flagged as malware and mark it clean or not.

All of this should be bubbled up into the far VBR Windows application for me.
Post Reply

Who is online

Users browsing this forum: Amazon [Bot] and 165 guests