Veeam-PerformScanBackup

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This Microsoft Sentinel playbook with an incident trigger performs antivirus scan on Veeam backup using VbrHostName, BackupObjectId, MachineDisplayName custom incident fields to identify backup. Indicates results as incident comments.

Attribute Value
Type Playbook
Solution Veeam
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 2
function Built-in 0 2
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Add_comment_to_incident_(V3) post /Incidents/Comment —
Add_comment_to_incident post /Incidents/Comment —

function (Built-in)

Action Method Endpoint Other
GetSession_ — — functionId=[format('{0}/functions/GetSessionAsync', variables('functionAppId'))]
StartBackupScanAV — — functionId=[format('{0}/functions/StartBackupScanAV', variables('functionAppId'))]

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Veeam