Skip to main content

Poll for new Veeam Backup & Replication Events and Open a Case - Workflow Template

Creates a case in Torq for malware events detected by Veeam Backup & Replication.

Updated yesterday

This Torq workflow template is designed for rapid incident response to malware events detected by Veeam Backup & Replication. It streamlines the process of creating and managing cases within Torq by auto-generating a case with predetermined severity levels and service level agreements (SLAs) based on the severity of the malware alert. For "Warning" alerts, cases are given HIGH priority with a 4-hour SLA, while "Error" alerts marked as Infected escalate to CRITICAL severity alongside a 1-hour SLA. An integrated Runbook is also attached to guide through the resolution process, ensuring efficient and effective response to potential security incidents.

Use Cases

Case Management , DSPM

Workflow Breakdown

  1. Upon detection of malware events, creates a case in Torq to investigate and resolve the issue.

  2. Sets the severity and SLA for each case in Veeam based on the alarm status.

  3. If the Veeam ONE alarm status is Warning, the Torq severity is set to HIGH , and the SLA is 4 hours.

  4. If the Veeam ONE alarm status is Error severity is Infected, the Torq severity is set to CRITICAL, and the SLA is 1 hour.

  5. Attaches a predefined Runbook

Vendors

Utils, Torq Cases

Did this answer your question?