Veritas
Veritas for Logpoint SIEM normalizes Veritas Backup Exec and Veritas NetBackup events.
Package Details
Veritas components:
-
Compiled Normalizers
-
VeritasBackupExecCompiledNormalizer
- DirectoryVeritasNetBackupCompiledNormalizer
-
-
Normalization Package
- LP_Veritas Exec Backup
Enhancement
Description | Issue ID | Reference ID |
---|---|---|
Added Syslog Collector based Veritas log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template. |
KB-22724 |
- |
Past Release
Varonis v5.0.2
Supported On: Logpoint v6.6.0 and later
SHA256: 7b9983ceb8ec67f71903e17807b921f7295d2b3a77e3b5e2a5141f8fe29a171f
Download: Veritas_release_5.0.2.pak
Supported Version
- Veritas Backup Exec
- Veritas NetBackup
Log Formats
Veritas Backup Exec
JSON
Log Sample<11>Jan 25 10:11:51 AABBCC.corp.group.local Backup_Exec[0]: {"EventTime":"2021-1-25 10:11:51","Hostname":"John","Keywords":"36028797018963968", "EventType":"ERROR", "SeverityValue":4, "Severity":"ERROR","EventID":34113, "SourceName":"Backup Exec","TaskValue":0,"RecordNumber":12345,"ExecutionProcessID":0, "ExecutionThreadID":0, "Channel":"Application","EventData":"<Data>Backup Exec Alert: Job Failed\n(Server: \"XXXXXX\") (Job: \"Inventory Tapes - Exchange 2\")Inventory Tapes - Exchange 2 -- The job failed with the following error: Library Error - attempt to clean a drive in a library with expired or bad cleaning media.\r\n</Data><Data>https://logpoint.com/entt?product=BE&module=eng-event&error=V379xxxxx&build=retail&version=xx.x.xxxx.xxxx&language=EN&os=Windows</Data>", "EventReceivedTime":"2020-12-01 10:11:52","SourceModuleName":"wineventlog_in","SourceModuleType":"im_msvistalog"}
Veritas Net Backup
JSON
Log Sample<14>Jan 25 11:26:41 John nbjm: {"EventTime":"2021-1-25 11:26:41","Hostname":"John","Keywords":"36028797018963968","EventType":"INFO", "SeverityValue":2,"Severity":"INFO","EventID":23,"SourceName":"nbjm","TaskValue":0, "RecordNumber":38196513,"ExecutionProcessID":0,"ExecutionThreadID":0,"Channel": "Application","Message":"sending command CONTINUE to BPBRM to continue backup for job (backupid = SPSVORA-DB111_1111111111)","Opcode":"Info","EventData":"<Data>CONTINUE</Data><Data>SPSVORA-DB111_1111111111</Data>","EventReceivedTime":"2021-1-25 11:26:41","SourceModuleName":"wineventlog_in","SourceModuleType": "im_msvistalog"}
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.