Bring your knowledge and expertise while creating blogs and podcasts
Recently active
1. Two Backup Methods, One Recovery Console Veeam provides two distinct methods for backing up Oracle databases. The first is image-level backup with application-aware processing, where VBR takes a VM-level or agent-level backup and handles Oracle archived redo logs as a guest processing subtask. The second is the Veeam Plug-in for Oracle RMAN, which integrates directly with Oracle's native Recovery Manager and sends backup data to a Veeam repository through the RMAN SBT (System Backup to Tape) interface.Both methods feed into the same recovery tool: Veeam Explorer for Oracle. Explorer can restore databases from either backup type through a single interface. The key difference is what each method captures and what recovery options each enables. Capability Image-Level Backup RMAN Plug-in Backup scope Entire VM or volume (includes OS, Oracle binaries, database) Database only (data files, control files, archived logs) Point-in-time restore
It was Christmas Eve. Most people were wrapping gifts, winding down, and logging off early. But for one of our clients a construction company with decades of project data, intellectual property, and live customer records, that night would become one of the most terrifying in the company's history. A double-encryption ransomware attack had just taken down every system. Completely dark. Several other construction companies across the region were affected by the same attack that night. What made this attack different wasn't just its timing. The attackers were sophisticated. They didn't just encrypt the production environment they deleted the on-site Veeam Backup & Replication server, wiped the local backup copies, and went after the cloud backup repository too. I was a deliberate, calculated attempt to leave no recovery path. They almost succeeded. When the Call Came InAs a managed service provider, we know that data emergencies don't respect holidays. The moment we received the aler
Recently a customer asked me: “Is it actually a problem if I add a branch office with ESXi hosts that are managed by a vCenter to Veeam as standalone hosts instead of adding the vCenter? What impact does that have?” The short answer: Yes, it can have noticeable impact — functionally, operationally, and also in terms of backup consistency when VMs are moving (with vMotion). Best practice in general is to add the vCenter as the management instance in Veeam, not the individual ESXi hosts. Okay, but why? What is vCenter — and why is it more than “just” a GUI? vCenter Server is the central management instance for VMware vSphere environments. It centrally manages objects such as clusters, hosts, VMs, folders, resource pools, tags, roles/permissions, HA/DRS, and many automation features. For backup solutions, vCenter is important because it provides a stable, always up-to-date inventory and object referencing ID (keyword: MoRef). Moe? Like that bartender from The Simpsons? Äh no — tha
1. This Is Not Troubleshooting Troubleshooting is what you do when a job fails and you want to fix it. Forensics is what you do when a job has been failing for three weeks and nobody noticed, a VM dropped out of protection and nobody caught it, or a ransomware event hit and you need to prove your last clean restore point. The question is not "how do I fix this job." The question is "what exactly happened, when did it start, what was affected, and can I prove it."Forensics requires a different mindset than break-fix. You are not looking for the current error. You are reconstructing a timeline. You need session history, task-level detail, bottleneck data, and alarm records across a window of days or weeks. VBR stores all of this. The trick is knowing where to look and how to correlate it. 2. Where the Logs Live VBR keeps two categories of evidence: the configuration database (PostgreSQL in v13, formerly SQL Server Express) and the file system logs. Database (Session and Task Records) Eve
When a full restore is the wrong move When SQL breaks, the first request is usually narrower than “restore the VM.” More often it is “get this database back to before the bad change” or “show me what was in last night’s backup.” That is the sort of job Veeam Explorer for Microsoft SQL Server handles well.It opens a SQL-aware view into a Veeam Backup & Replication restore point and lets you pick the recovery method that fits the problem in front of you: restore a database, recover to a specific time, roll back to just before a bad transaction, publish a database from backup, run instant recovery, or export schema and data without rebuilding an entire machine.If the backup captured SQL correctly, the workflow is familiar whether the source came from a VM backup, Veeam Agent for Windows, or the Veeam Plug-in for Microsoft SQL Server. You can launch the Explorer from the VBR console, from the Windows Start menu, or through PowerShell. Opening the tool is easy. The part that matters is
This is the first article in a multi-part series on From Reactive to Proactive: Running Veeam Like a Platform. In the next article, we'll look at the step-by-step process for completing this. Most Veeam environments don’t start out broken.They start out reactive.Something fails → you fix it.A job warns → you investigate it.Storage fills up → you scramble to add more.And for a while, that works.Until it doesn’t.Because as your environment grows, reactive operations turn into:Constant firefighting Unpredictable performance Unclear recovery expectationsAt some point, you realize:You’re not running a backup tool anymore.You’re running a data protection platform.And platforms need to be operated differently. What “Reactive” Actually Looks LikeMost teams don’t realize they’re reactive—it just feels normal.You check failures after they happen You deal with warnings when they pile up You only look at performance when it’s slow You test restores when someone asksNothing is technically “wrong.”B
Veeam participated in HPE Tech Jam Orlando 2026 as a Silver Sponsor, reinforcing its strategic alliance with HPE and underscoring its joint commitment to advancing innovation in cyber resilience and data protection.The Veeam team delivered a special breakout session titled “Securing Your Hybrid Cloud with Veeam and HPE”. The session demonstrated how the Veeam Data Platform integrates seamlessly with HPE Private Cloud and storage solutions to protect hybrid environments, covering virtual, physical, and containerized workloads.Attendees of this session explored the expanding HPE and Veeam partnership, which included new support for HPE Morpheus VM Essentials Software and V13 enhancements across backup, recovery, and management.The session also emphasized advanced threat detection, secure recovery, and intelligence-driven insights, enabling organizations to respond to cyberattacks with greater confidence. In addition, the recent acquisition of Securiti AI accelerated the integration of
In recent months, Veeam has been making a series of changes to its certifications. We have changes in the certification model and in the format of the courses and teaching methods. I'll discuss the main changes and alterations on this topic here. Retired CertificationsThe Veeam certification path has always consisted of two levels of knowledge. These are:VMCE (Veeam Certified Engineer) – a technical level focused on operationsVMCA (Veeam Certified Architect) – an advanced level focused on architecture design and project implementationFrom the beginning, this model was very well received by the market and widely adopted. Its success is largely due to the absence of an entry-level (foundation) certification. As a result, the certification exams have always been considered highly challenging; however, the knowledge gained has consistently delivered significant value, enabling rapid career growth and professional development.However, with continuous technological advancements and the evolu
Today, March 31, is World Backup Day. This date exists because, even today, I still see many companies continuing to lose critical data. In the vast majority of cases, these losses are not related to a lack of technology, but rather to strategy and process failures, and especially to an underestimation of risk.And these risks are not limited to lost files or servers with software issues. They involve systemic failures in operations, security, and even architecture. Real CaseI will cover a real case I went through recently, where I will share more details not only about the problem, but also about how it was possible to recover from the disaster. The ScenarioIn a virtualization environment made up of multiple clusters, a ransomware attack impacted the environment and made a number of virtual servers unavailable. Fortunately (or thanks to good judgment), only one cluster was affected. ContainmentIn parallel, the entire security team immediately began working to understand the incident a
It started as a routine alert—unusual login activity flagged by our monitoring system. Within minutes, multiple backup jobs began failing, and that’s when we knew: this wasn’t random—it was targeted.The attacker had gained access using compromised credentials and was attempting something we’ve all seen becoming more common—destroy the backups first before encrypting production systems.But this time, things didn’t go as planned.Our backup environment was built with immutability and zero-trust principles using Veeam Backup & Replication integrated with hardened repositories. Even though the attacker had access to certain systems, they couldn’t modify or delete backup data due to immutable storage policies.While the security team contained the breach, we verified the backup integrity.Everything was intact.A few production workloads were still impacted—some files were encrypted before containment—but recovery was where the real difference showed.Instead of panic, we executed a clean re
This blog post was inspired by an excellent article that explores recovery scenarios beyond the typical restoration approaches often covered.In-place upgrades represent the standard and vendor-recommended approach for advancing Veeam Backup & Replication (VBR) to newer releases, ensuring continuity of configuration, and retention of job etc without requiring a full reinstallation. But without a test lab, you are essentially performing a high-wire act. While everyone talks about restoring data during “World Backup Day”, few share stories of how protecting the protector. Veeam’s own configuration backup can literally rescue your Veeam Backup and Replication (VBR) when an upgrade goes sideways. You can take a look at this Veeam kb2645. Note: Exiting skips finalization steps that initialize IdentityService config, DB schemas, certs, and token dirs, leaving services “running” but incomplete leaves VBR unusable. Ensures you get the wizard that displays the completion of the upgrade.Veeam
This is the English version of a selected article from Climb Japan Engineer Blog series. When you use Veeam Backup & Replication to process a backup or backup copy to be saved in the object storage such as Amazon S3, there might be a case where you receive the alert message below.Subject: [Warning] Background checkpoint removal. Backup server: <your Veeam server name>Body text: Failed to remove checkpoints from the backup repository <your repository name>This alert is issued when obsolete checkpoint (i.e. restore point) removal process on the object storage where backup data are stored has been failed.Removal of such checkpoints has been a part of the backup job in Veeam Backup & Replication Version 12.1 and earlier. From Version 12.2 onwards, the checkpoint removal is an independent task and can be processed in the background contineously.Separating the removal task from the backup job was a good update to help reduce the object storage loads.Even if you receive th
1. Why Job Design Matters Anybody can create a backup job. Open the wizard, add VMs, pick a repository, set a schedule, click finish. The job runs. The question is whether it runs well at scale, whether it makes SureBackup testing practical, whether it handles application consistency correctly, and whether it does not create operational headaches six months from now when the environment has grown.Job design is the difference between a backup environment that runs itself and one that requires constant intervention. Bad job design produces jobs that run too long, compete for proxy and repository resources, break application log chains, make restore operations slow, and make SureBackup configurations a nightmare. This article covers the patterns that work and the anti-patterns that do not. 2. Per-VM Backup Chains vs Per-Job Chains VBR offers two backup file layout options: per-VM backup chains (one backup file chain per VM) and per-job backup chains (one backup file chain for the entire
Immutable backups are one of the best things to happen to data protection.They’ve become the go-to answer for ransomware resilience—and for good reason:Backups can’t be deleted They can’t be modified Attackers can’t encrypt themThat’s a huge win.But here’s the part that doesn’t get said enough: Immutability is a layer of protection—not a complete strategy.I’ve seen environments check the “immutable” box and assume they’re covered.They’re not.Because when something actually goes wrong, immutability alone doesn’t guarantee you can recover cleanly, quickly, or safely.Let’s talk about what else you actually need. 1. Recovery Testing (Because “Protected” Doesn’t Mean “Recoverable”)You can have perfectly immutable backups that are:Corrupted Incomplete Misconfigured Or just… not usable the way you expectIf you haven’t tested restores, you’re still guessing.What you should be testing:Full VM restores File-level recovery Application item restores (SQL, AD, email) Instant Recovery performance
As a follow-up to my previous blog on the VSA HA Clustering setup, I decided to do a companion blog about using Veeam ONE for monitoring. Check it out below and link to my blog.Monitoring Your Veeam VSA HA Cluster with Veeam ONE Monitoring Your Veeam VSA HA Cluster with Veeam ONE Getting visibility into your Veeam VSA High Availability (HA) Cluster is critical for ensuring backup continuity. Veeam ONE provides the dashboards, alarms, and reporting you need to stay ahead of issues before they impact your recovery objectives. This post walks through configuring Veeam ONE to effectively monitor your VSA HA Cluster — from initial connection through tuning alarm thresholds and automating the whole thing with PowerShell via the Veeam ONE REST API.What Is the Veeam VSA HA Cluster?The Veeam VSA HA Cluster provides redundancy for your Veeam Backup & Replication environment by pairing a primary and secondary node. If the primary node fails, the secondary automatically takes over, maintainin
World Backup Day is often treated as a reminder—a checklist item to verify that backups exist, are recent, and are recoverable. But for those of us working in infrastructure and disaster recovery, it represents something much more concrete: the difference between operational continuity and complete outage. This is not a theoretical discussion. This is a real incident.This is my experienceThe Incident: Ransomware at ScaleRecently, I was involved in managing a critical ransomware attack that impacted a large virtualized environment. After an initial assessment, it became clear that we were dealing with a full-scale ransomware infection.Roughly “150 virtual machines” in a VMware environment were affected. The situation escalated quickly, requiring immediate containment measures. All impacted systems were powered off to prevent further propagation.At that point, a **war room** was established, and we moved into a structured incident response process:-Detection & Analysis-Containment-
This is the English version of a selected article from Climb Japan Engineer Blog series.-----Veeam Backup & Replication enables the agentless protection of Hyper-V virtual machines. In order to maintain the data integrity of Hyper-V VMs, when you process a Veeam backup, a temporary Hyper-V checkpoint is automatically created and it is then deleted when the data capture is completed.However, in some exceptional situations, e.g. as a result of antivirus software interference, the checkpoint may remain on the protected VM. In that case, you might see the remaining checkpoint named “Veeam Recovery Checkpoint (XXXX)” on the Hyper-V Manager screen as below. The red marked section shows the remaining checkpoint. Note the UI is in Japanese.The Hyper-V checkpoint size may increase as time goes by, because it will reflect the protected VM’s data changes. Therefore, if the checkpoint is left there for a longer period, the size may become large enough to negatively impact the performance of th
While working in a lab with multiple silos, minimal change control, and backup processes in place, not everyone informs the backup administrator of new servers or devices added to the infrastructure that require backups. As the backup administrator, it's my responsibility to ensure that all servers have a reliable backup and can be restored in the event of a disaster. I make that extra effort so that, in situations like the one below, we can get everything back online in a timely manner.It was an early normal Monday morning, and I was reviewing the weekend backups when a Teams call came in from our Network Lead for the lab.When the Network Goes QuietAt first, a few users reported they couldn’t access shared drives.Then applications started timing out.Then monitoring lit up.Within minutes, it was clear: We weren’t dealing with a slow network. We were dealing with a broken one.Core services were unreachable.Critical systems were effectively offline.And the worst part?We didn’t imme
Was working today doing some tape stuff and when testing my PowerShell script to create GFS pools noticed that when you go into the Advanced settings for the Daily, Weekly, etc. section of the pool properties you see two monthly and no quarterly.I have logged this on the Forums as a potential bug but wanted to give a heads-up as it is just cosmetic, mainly the main page for the retention options shows Quarterly proper (which I thought they were removing?).
Hi all, I wanted to share the new Veeam Ports MCP server with the community. This gives you the ability to interact with the Veeam Ports underlying database to create rich designs using LLM clients that support MCP, like Claude and VS Code.https://github.com/shapedthought/veeam-ports-mcpTo install in Claude:Install Python Install UV Run: claude mcp add veeam-ports -- uvx veeam-ports-mcp Update your Claude desktop configuration file: macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json { "mcpServers": { "veeam-ports": { "command": "uvx", "args": ["veeam-ports-mcp"] } }}I am still working to improve it to provide greater fidelity. Currently, the best way to work with it is to ask the AI to walk you through putting a design together; that way, it will guide you in selecting what you need in the correct order.There is also a tool called generate_app_import. When you're happy with the design, you can a
The VBR REST API matters because it gives you direct access to the backup server itself without going through Enterprise Manager. Start with what it actually is The VBR REST API runs over HTTPS on port 9419.It uses OAuth 2.0 bearer tokens, returns JSON, and publishes an OpenAPI specification. The backup server exposes Swagger directly, which makes it easy to inspect the available endpoints without digging through scattered examples first. That part is genuinely helpful, because the API is large enough now that guessing your way through it is a waste of time.The practical reason to use it instead of the PowerShell module comes down to three things:• it is language-agnostic• it works remotely without needing the Veeam PowerShell module installed on the caller• it fits better into multi-server and non-Windows automation patterns Connectivity is simple, but you should verify it first The API service starts with VBR. There is no separate install and no extra feature toggle to go hunting fo
Last week I attended RSAC and as stated in a previous post had a great time.However, nothing in life is perfect and I had one conversation that got me worried. The person in question is much more “in the know” than I am when it comes to the IT industry. He claimed that blogging is basically dead now. It has been washed away by a tidal wave of AI generated content and has permanently removed the need for real bloggers. “No one believes that anyone actually writes anything anymore”. Along with that IT communities are under threat, if you don’t need bloggers and content creators then why have these groups of people? The can be easily and cheaply replaced by AI Agents. I wanted to ask everyone here what they thought and if there is anything we can do to save our brands?For my part I have decided to always try and post a video along with any written content that I create. The BVLOG!! If you can pronounce that you should win an award right off the bat!
My belated contribution to World Backup Day."Man kütt ja zu nix" - as they say in the Rhineland ( You Never Get Around To It ). I learned the value of backups very early in my professional life.As a dual-study student during my first practical phase, I accidentally deleted the root directory of a server - specifically, the server that managed access control for all branches in western Germany.Luckily, my colleagues didn't behead their panicked young employee, but remained calm and restored the deleted data from a backup. At that time, it wasn't a Veeam backup; it must have been either a late ADSM version or an early TSM version.In any case, this experience has shaped me ever since: Firstly: It was great to have had such colleagues at that time. And secondly: Always have a backup of your data and systems! Many years later, data backup is my main professional task.Thanks to Veeam, regular system and data backups are no longer a major problem. It just works 😉But the threats have changed.
IntroIn a previous article I wrote about the type of storage a customer can use and write their backup to.Some days ago, a user in the Veeam Community asked why, according to Veeam's calculator, S3 object storage is no longer more efficient in terms of space (with immutability and GFS) than storage using XFS/ReFS technology.After answering, I decided to explore the topic further by putting myself in the shoes of a customer who has to make a choice in terms of the costs associated with the space used. That's why I want to tell you what happened with a customer.When I start a new backup infrastructure project, there always comes a time when I have to decide what type of storage repository to use. When I submit a plan to the customer, I often hear them say: Why should I spend more and use more space than requested?It usually happens when the storage budget is already tight, immutability is mandatory, and you are stuck in the middle between security, costs, and unrealistic expectations.Sit
How NTP Architecture Impacts MFA in Veeam Software Appliances — And What Happens When Clocks DriftMulti‑Factor Authentication (MFA) in Veeam’s software appliances relies heavily on accurate system time. This is because MFA one‑time passwords (TOTPs) are time‑based. If the appliance clock drifts even slightly, MFA will break — often in confusing ways.In this post, we break down:What NTP is doing inside the Veeam Software Appliance Why MFA fails when clocks drift How time desynchronization can escalate Worst‑case recovery when you’re completely locked outWhat NTP Architecture Is Doing Inside Veeam Software AppliancesVeeam Software Appliances use chrony (the NTP client on Rocky Linux) to synchronize system time with configured NTP servers. This ensures that all time‑dependent security functions — including MFA and OTP generation — remain accurate.Veeam imports NTP configuration through:Veeam Host Management Console (UI) where admins can set NTP servers Veeam Live OS ISO environment, whi
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.