Hub
Backup

Veeam Backup & Replication Syslog

Veeam Backup & Replication 13.1 syslog records for one backup server: nightly and ad-hoc backup job sessions over 400 VMs, restore point creation and retention, web UI logons of a sixteen-person backup team, manual point removals and one planned repository retirement, as ECS JSON with the native syslog record in event.original. Recurring episodes show a Backup Administrator granted access after repeated denials and then removing a restore point.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/backup-veeam-vbr/generator.yml \
  --id vbr \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
10010Restore point created49.0% measured sharefile
10050Restore point deleted (SYSTEM retention and user removals)43.8% measured sharefile
44003User authorization granted4.8% measured shareauthentication
190Backup job finished1.5% measured shareprocess
44002User authorization denied0.8% measured shareauthentication
110Backup job started by a user0.2% measured shareprocess
28200Backup repository deleted0.01% measured share (once per run)configuration

Realism Features

  • Two UTC hour-of-day curves add up: the working-hours curve peaks at 9.7 records/h in 08-17 UTC, the backup window runs at 144/h in 20-06 UTC and 54/h by day. About 2,300 records per day with a ±10% day-to-day variation. Steps of one logon are seconds to minutes apart rather than milliseconds (repeated denials: median 91 s).
  • Twelve jobs protect 400 VMs. Scheduled sessions follow one another and begin with their first 10010, since Veeam sends 110 only for user-started sessions; VMs finish in random order, and each 10010 carries the snapshot time as DateTime (median 47 s before the record). SYSTEM retention removes the oldest point (10050) right after a new one when a VM exceeds its job retention count.
  • Sixteen operators log on to the web UI from their workstation or over VPN, one session at a time (median 20 minutes): six Backup Administrators about 10 times a day, ten Backup Operators about 5. Mistyped passwords and passwords saved before a PAM rotation or expiry produce 44002 denials (Reason 1) before the grant; 8% of logon attempts include a denial and 5% two or more.
  • After 4% of logons an operator starts an idle job: 110 with Flags=1, its points ahead of scheduled work and 190 with the same JobSessionID. Only Backup Administrators remove points manually, one to three after 8% of their sessions. Once per run, at a working-hours time 6-72 hours after the start of the run, an administrator retires the unused secondary repository (10050, then 28200) in both modes, outside the anomaly.
  • Every session succeeds and every point is full. Rates, retention counts, team and inventory size and the hour curves are design choices; timestamps, including DateTime, are UTC with microseconds rather than the server's local offset. Episodes use an administrator's primary address only and always remove exactly one point; with anomaly_mode true the chain's parts count higher by the episodes' own records (one per episode for each part, seven a week at the default interval).
  • The envelope mirrors Veeam's published examples, which omit the PRI prefix, and XML-valued parameters keep literal inner quotes, so a strict RFC 5424 parser may reject them. Byte parity with a real capture and SIEM parser compatibility are not verified; the ECS mapping is the generator's own.

Sample Output

{
  "@timestamp": "2026-09-01T18:42:20.609177+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "kind": "event",
    "module": "veeam",
    "dataset": "veeam.vbr.syslog",
    "code": "10050",
    "category": [
      "file"
    ],
    "action": "restore_point_deleted",
    "type": [
      "deletion"
    ],
    "outcome": "success",
    "original": "1 2026-09-01T18:42:20.609177+00:00 VBRSRV01 Veeam_MP - - [origin enterpriseId=\"31023\"] [categoryId=0 instanceId=10050 OibID=\"b7c7dc10-4901-46d1-a938-5c3ab7492ee2\" OriginalOibID=\"b7c7dc10-4901-46d1-a938-5c3ab7492ee2\" VmRef=\"vm-218\" VmName=\"SRV-INF18\" ServerName=\"pdcsrv01.contoso.test\" DateTime=\"08/27/2026 07:11:45\" IsCorrupted=\"False\" Platform=\"0\" StorageSize=\"19150786560\" RepositoryID=\"88788f9e-d8f5-4eb4-bc4f-9b3f5403bcec\" IsFull=\"True\" UserFullInfo=\"\u003cModifiedUserInfo fullName=\"TECH\\veeamadmin\" loginType=\"0\" /\u003e\" VbrHostName=\"vbrsrv01.contoso.test\" VbrVersion=\"13.1.1.18\" Version=\"1\" Description=\"Restore point for VM \u0027SRV-INF18\u0027 has been removed by user TECH\\veeamadmin.\"]"
  },
  "message": "Restore point for VM \u0027SRV-INF18\u0027 has been removed by user TECH\\veeamadmin.",
  "host": {
    "name": "VBRSRV01"
  },
  "user": {
    "name": "veeamadmin"
  },
  "veeam": {
    "event_id": 10050,
    "app": "Veeam_MP",
    "severity": "warning",
    "enterprise_id": 31023,
    "category_id": 0,
    "parameters": {
      "DateTime": "08/27/2026 07:11:45",
      "Description": "Restore point for VM \u0027SRV-INF18\u0027 has been removed by user TECH\\veeamadmin.",
      "IsCorrupted": "False",
      "IsFull": "True",
      "OibID": "b7c7dc10-4901-46d1-a938-5c3ab7492ee2",
      "OriginalOibID": "b7c7dc10-4901-46d1-a938-5c3ab7492ee2",
      "Platform": "0",
      "RepositoryID": "88788f9e-d8f5-4eb4-bc4f-9b3f5403bcec",
      "ServerName": "pdcsrv01.contoso.test",
      "StorageSize": "19150786560",
      "UserFullInfo": "\u003cModifiedUserInfo fullName=\"TECH\\veeamadmin\" loginType=\"0\" /\u003e",
      "VbrHostName": "vbrsrv01.contoso.test",
      "VbrVersion": "13.1.1.18",
      "Version": "1",
      "VmName": "SRV-INF18",
      "VmRef": "vm-218"
    }
  }
}

Parameters

ParameterDefaultDescription
server_nameVBRSRV01Syslog hostname and host.name
server_fqdnvbrsrv01.contoso.testVbrHostName
version13.1.1.18VbrVersion
user_domainTECHDomain prefix in Description, UserName and UserFullInfo
hypervisor_serverpdcsrv01.contoso.testServerName of the protected VMs
active_repository_id88788f9e-d8f5-4eb4-bc4f-9b3f5403bcecRepository used by all jobs
repository_ided8c61cc-77f0-4f40-b73e-8c92d4a6fb11Secondary repository retired once
repository_nameBackup Repository 01Name of the secondary repository
retired_point_id882ace9a-6308-4f2b-bd12-88f004de0162Pre-existing point on the secondary repository
anomaly_interval_hours24Episode interval in source hours, 2 to 8,760
anomaly_modetruetrue adds recurring episodes; false emits background only

Related Generators