Integrate Veeam Backup and Replication. EventTracker v9.x and above

Similar documents
SECURE FILE TRANSFER PROTOCOL. EventTracker v8.x and above

Integrate Dell FORCE10 Switch

Integrate Palo Alto Traps. EventTracker v8.x and above

Integrate Symantec Messaging Gateway. EventTracker v9.x and above

Integrate Sophos Appliance. EventTracker v8.x and above

Integrate Bluecoat Content Analysis. EventTracker v9.x and above

Integration of Phonefactor or Multi-Factor Authentication

Integrate NGINX. EventTracker v8.x and above

Integrating Barracuda SSL VPN

Integrate Barracuda Spam Firewall

Integrate HP ProCurve Switch

Integrate Microsoft ATP. EventTracker v8.x and above

Integrate Salesforce. EventTracker v8.x and above

Integrate Sophos Enterprise Console. EventTracker v8.x and above

Integrate Sophos UTM EventTracker v7.x

Integrate Microsoft Office 365. EventTracker v8.x and above

Integrate EMC Isilon. EventTracker v8.x and above

Receive and Forward syslog events through EventTracker Agent. EventTracker v9.0

Integrate Microsoft Antimalware. EventTracker v8.x and above

Integrating Terminal Services Gateway EventTracker Enterprise

Integrate TippingPoint EventTracker Enterprise

Integrating Imperva SecureSphere

Integrate Windows PowerShell

Integrate Aventail SSL VPN

Integrate Fortinet Firewall. EventTracker v8.x and above

Integrate Saint Security Suite. EventTracker v8.x and above

Integrate pfsense EventTracker Enterprise

Integrate IIS SMTP server. EventTracker v8.x and above

Integrate Cb Defense. EventTracker v8.x and above

How To Embed EventTracker Widget to an External Site

Integrating Microsoft Forefront Unified Access Gateway (UAG)

Integrate Cisco IronPort Security Appliance (ESA)

Integrate Microsoft Hyper-V Server

Integrating Cisco Distributed Director EventTracker v7.x

Integrate F5 BIG-IP LTM

Integrate Malwarebytes EventTracker Enterprise

Port Configuration. Configure Port of EventTracker Website

Integrate A10 ADC Publication Date: September 3, 2015

Integrate Citrix Access Gateway

Integrate Cisco IOS Publication Date: April 15, 2016

Integrating Cyberoam UTM

Product Update: ET82U16-029/ ET81U EventTracker Enterprise

Integrate Meraki WAP. EventTracker Enterprise. EventTracker 8815 Centre Park Drive Columbia MD

Integrate Juniper Secure Access VPN

Integrate VMware ESX/ESXi and vcenter Server

Integrate MySQL Server EventTracker Enterprise

Integrate Akamai Web Application Firewall EventTracker v8.x and above

8815 Centre Park Drive Columbia MD Publication Date: Dec 04, 2014

Geolocation and hostname resolution while Elasticsearch indexing. Update Document

Integrate McAfee Firewall Enterprise VPN

Integrate Viper business antivirus EventTracker Enterprise

Integrate Citrix NetScaler

Integrate WatchGuard XTM. EventTracker Enterprise

Integrating Microsoft Forefront Threat Management Gateway (TMG)

Integrate Trend Micro InterScan Web Security

Integrate Check Point Firewall. EventTracker v8.x and above

IIS Web Server Configuration Guide EventTracker v8.x

How to Configure ASA 5500-X Series Firewall to send logs to EventTracker. EventTracker

Integrate Trend Micro Control Manager. EventTracker v8.x and above

Integrate Microsoft IIS

EventTracker v7.x. Integrating Cisco Catalyst. EventTracker 8815 Centre Park Drive Columbia MD

Integrating LOGbinder SP EventTracker v7.x

Enhancement in Network monitoring to monitor listening ports EventTracker Enterprise

Enable Auditing in Open LDAP on Linux Server

Integrate Cisco Sourcefire

Integrate Apache Web Server

Security Scorecard in Flex Dashboard

Secure IIS Web Server with SSL

Configuring TLS 1.2 in EventTracker v9.0

Integrate Cisco Switch

Integrate Cisco VPN Concentrator

IIS Web Server Configuration Guide EventTracker v9.x

Enhancement in Agent syslog collector to resolve sender IP Address EventTracker Enterprise

Integrate APC Smart UPS

Service Pack ET90U Feature Document

Event Correlator. EventTracker v8.x

Agent Installation Using Smart Card Credentials Detailed Document

Agent health check enhancements Detailed Document

Process Termination. Feature Guide

Integrate Routing and Remote Access Service (RRAS) EventTracker v8.x and above

Integrate Kaspersky Security Center

EventTracker v8.2. Install Guide for EventTracker Log Manager. EventTracker 8815 Centre Park Drive Columbia MD

EventTracker: Backup and Restore Guide Version 9.x

EventTracker Upgrade Guide. Upgrade to v9.0

Feature List. EventTracker v9.0

Monitoring SharePoint 2007/ 2010/ 2013 Server using EventTracker

Remote Indexing Feature Guide

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Agent Direct Log Archiver Configuration Guide

Integrate Clavister Firewall

Feature List. EventTracker v7.6. EventTracker 8815 Centre Park Drive Columbia MD Publication Date: Sep 15, 2014

Integrate Grizzly steppe attacks detection script

Installation Guide. EventTracker Enterprise. Install Guide Centre Park Drive Publication Date: Aug 03, U.S. Toll Free:

EventTracker Manual Agent Deployment User Manual Version 7.x

EventTracker Manual Agent Deployment User Manual

EventVault Introduction and Usage Feature Guide Version 6.x

Installation Guide Install Guide Centre Park Drive Publication Date: Feb 11, 2010

New Features Guide EventTracker v6.2

Upgrade Guide. Upgrading to EventTracker v7.1 Enterprise. Upgrade Guide Centre Park Drive Publication Date: Apr 11, 2011.

Adding Tokens in Flex Report

Transcription:

Integrate Veeam Backup and Replication EventTracker v9.x and above Publication Date: September 27, 2018

Abstract This guide provides instructions to configure VEEAM to send the event logs to EventTracker Enterprise. Once events are configured to send to EventTracker Manager, alerts, dashboard and reports can be configured into EventTracker. Scope The configurations detailed in this guide are consistent with EventTracker Enterprise version 9.x and later, and VEEAM v9.5. Audience VEEAM users, who wish to forward event logs to EventTracker Manager and monitor events using EventTracker Enterprise. The information contained in this document represents the current view of EventTracker. on the issues discussed as of the date of publication. Because EventTracker must respond to changing market conditions, it should not be interpreted to be a commitment on the part of EventTracker, and EventTracker cannot guarantee the accuracy of any information presented after the date of publication. This document is for informational purposes only. EventTracker MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, this paper may be freely distributed without permission from EventTracker, if its content is unaltered, nothing is added to the content and credit to EventTracker is provided. EventTracker may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from EventTracker, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. The example companies, organizations, products, people and events depicted herein are fictitious. No association with any real company, organization, product, person or event is intended or should be inferred. 2018 EventTracker Security LLC. All rights reserved. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. 1

Table of Contents Abstract... 1 Scope... 1 Audience... 1 Overview... 3 Prerequisites... 3 Configure VEEAM to forward logs to EventTracker... 3 EventTracker Knowledge Pack (KP)... 5 Alert... 5 Knowledge Objects... 5 Categories... 5 Reports... 5 Import Knowledge Pack into EventTracker... 8 Import Alerts... 8 Import Knowledge Objects... 9 Import Category... 11 Import Tokens Template... 12 Import Flex Reports... 13 Import Dashboards... 15 Verify Knowledge Pack in EventTracker... 18 Verify Alerts... 18 Verify Knowledge Object... 19 Verify Category... 20 Verify Token Values... 21 Verify Flex Reports... 22 Verify Dashboards... 23 Sample Dashboards... 25 2

Overview Veeam Backup & Replication is a software product developed by Veeam Software to back up, restore and replicate data on virtual machines. It was first released in 2008 and is part of the Veeam Availability Suite. Prerequisites EventTracker 8.x or later should be installed. Veeam Backup & Replication Tool should be installed. Configure VEEAM to forward logs to EventTracker Veeam logs are found in Event Viewer. EventTracker consumes the logs from the Event Viewer. Go to <%EventTrackerInstalledPath%>\Prism Microsystems\EventTracker\Agent. Run etaconfig. Select Event Filters tab, and then click the Filter Exception button. Figure 1 3

Select New to add an exception. Figure 2 In the Match in Source field type Veeam MP and click OK. Save and exit. Figure 3 4

EventTracker Knowledge Pack (KP) Once logs are received in EventTracker; category, reports and dashboards can be configured in EventTracker. Alert Veeam Backup and Replication License Expired: This alert is generated when the license for Veeam Backup and Replication tool is expired. Knowledge Objects Veeam Backup and Replication - Configuration changes: This knowledge object gives information about the configuration changes such as jobs created, modified or deleted. Veeam Backup and Replication - Jobs: This knowledge object gives information about the Backup jobs status. Categories Reports Veeam Backup and Replication - Configuration changes: This category gives information about the configuration changes such as jobs created, modified or deleted. Veeam Backup and Replication - Jobs: This category gives information about the Backup jobs status. Veeam Backup and Replication - Configuration changes: This report gives information about the configuration changes such as jobs created, modified or deleted. Figure 4 5

Logs Considered: Figure 5 Veeam Backup and Replication - Jobs Status: This report gives information about the Backup jobs status. Figure 6 6

Logs Considered: Figure 7 Veeam Backup and Replication - Connection details: This report gives information related to connection details. Logs Considered: Figure 8 Figure 9 7

Import Knowledge Pack into EventTracker Import Alerts Launch EventTracker Control Panel. Figure 10 Double click Export/Import Utility, and then click the Import tab. Click Alert option, and then click the browse button. 8

Figure 11 Figure 12 Click OK, and then click the Close button. Import Knowledge Objects Click Knowledge objects under Admin option in the EventTracker manager page. Click on Import option. Locate the file named KO_VEEAM.etko 9

Figure 13 Now select all the check box and then click Upload. Figure 14 10

Knowledge objects are now imported successfully. Click OK, and then click the Close button. Import Category Figure 15 Launch EventTracker Control Panel. Double click Export/Import Utility, and then click the Import tab. Figure 16 Click Category option, and then click the browse button. 11

Figure 17 Locate Category_VEEAM.iscat file, and then click the Open button. To import categories, click the Import button. EventTracker displays success message. Click OK, and then click the Close button. Import Tokens Template Figure 17 Logon to EventTracker Enterprise. Click the Admin menu, and then click Parsing Rules. Select Template tab, locate the Token_Template_VEEAM.ettd file. 12

Figure 18 Select all the reports by clicking on the check box. Click on the Import icon. Templates are now imported successfully. Figure 19 Click OK, and then click the Close button. Import Flex Reports Figure 20 Launch EventTracker Control Panel. Double click Export/Import Utility, and then click the Import tab. 13

Figure 21 Click Reports option, and select new (.etcrx) from the option. Figure 22 Locate the file named Reports_ VEEAM.etcrx and select all the check box. 14

Figure 23 Click the Import button to import the reports. EventTracker displays success message. Click OK, and then click the Close button. Import Dashboards Figure 24 In EventTracker 9.0, you can import dashlet. Following is the procedure to do that: 1. Login into EventTracker Enterprise Web console. 15

Figure 25 2. Go to My Dashboard option. Figure 26 16

3. Click on import button and select Dashlet_Veeam.etwd File. Figure 27 Figure 28 4. Click upload and select Dashboard which you want to import. 17

Figure 29 5. Click on Import button. It will upload all selected dashboards. Verify Knowledge Pack in EventTracker Verify Alerts Logon to EventTracker. Click the Admin menu, and then click Alerts. In Alerts search for Veeam to view Veeam Alerts. 18

Verify Knowledge Object Figure 30 Logon to EventTracker. Click the Admin menu, and then click Knowledge Object. In Knowledge Object Group Tree to view imported knowledge object, scroll down and click VEEAM group folder. Knowledge Objects are displayed in the pane. 19

Verify Category Figure 31 Logon to EventTracker. Click the Admin menu, and then click Category. In Category Group Tree to view imported category, scroll down and click VEEAM group folder. Category are displayed in the pane. 20

Verify Token Values Figure 32 Logon to EventTracker. Click the Admin menu, and then click Parsing Rules. In Token Value Group Tree to view imported token values, scroll down and click VEEAM group folder. Token values are displayed in the token value pane. 21

Verify Flex Reports Figure 33 Logon to EventTracker. Click the Reports menu, and then Configuration. Select Defined in report type. In Report Groups Tree to view imported Scheduled Reports, scroll down and click VEEAM group folder. Reports are displayed in the Reports configuration pane. 22

Verify Dashboards 1. Go to My Dashboard option. Figure 34 Figure 35 23

Click on customize dashlet icon. Figure 36 Figure 37 24

Sample Dashboards Veeam Backup and Replication Job Status Figure 38 25

Veeam Backup and Replication Configuration Changes Veeam Backup and Replication Job Details Figure 39 Figure 40 26