News, guidelines and various community projects
Recently active
We’re evaluating replacing out Windows VBR-servers with VSA, and I have set up a pilot machine. We need AD authentication to work for this, and I have joined the VSA to our domain.The main issue we have is that authentication is extremely slow and even if I can get “connected” pretty quick when I log in from the VBR-console, it can then take several minutes just to get past the splash screen. Even once logged in, I can get kicked out with some authentication error and “too many retries”. Also adding the AD-group to the “Veeam Administrator” role took forever and several retries. My strong suspicion is that SSSD used for this, is doing forest-wide queries, and since we are a huge company with many domains and trusts this is what takes time and causes timeouts. We’ve worked around this in other self-managed linux systems by using ldap as provider instead of “ad”, and limiting scope with ldap_serarch_base and filters, but not sure this is an option here, and pretty sure it wouldn’t be sup
In my latest blog article part 2 of Integration Veeam with CrowStrike, I'll walk through the steps of a recent implementation & integration of CrowdStrike with Veeam backup servers. Cyberattacks continue to target backup infrastructure because attackers know backups are often the last line of defense. Traditional antivirus solutions are no longer enough to protect modern backup environments, especially when ransomware actors specifically target backup repositories, backup servers, and privileged accounts.That’s where integrating CrowdStrike with Veeam Software can significantly improve your security posture.By combining Veeam’s ransomware detection and secure recovery capabilities with CrowdStrike Falcon’s endpoint protection and threat intelligence, organizations can better detect, contain, and recover from cyber incidents.In this lab guide, I’ll walk through the steps to implement and configure CrowdStrike integration with Veeam and explain how the two platforms complement each
Hello Veeam Community,With all the great conversations and content shared this month, I almost forgot — it’s time to vote for the Blog of the Month! Here are the top 6 picks ( and honestly, it was not an easy choice, you guys getting better and better 😻) ! Community, help us choose this month’s winner and award the badge!@PeteSteven , @Michael Melter , @Stabz , @matheusgiovanini , @Mohamed Ali , @Nico Losschaert Best of luck! Madi
Instantly bucket size is increasing. What could be the issue? What is the best practice to follow here? My concern is GCP storage.
Dear Community, What could be the possible issue?
Every now and then you get customer requests that initially knock you off your feet — because you can tell right away: this isn’t described anywhere in the documentation. Then it’s time to truly understand the problem, clarify the requirements properly (does the problem even exist in that form, or can it be solved differently?), research internally, potentially review a feature request including the use case — and finally think about how to help the customer pragmatically in the short term: the good old “workaround” or “self-fix.”That was the case here as well. A customer is using the standalone Veeam Plug-in for Oracle RMAN and wants to install the Veeam plug-in — however, in the customer’s environment it is intentionally used as unmanaged. At the same time, the rollout should be automated, and no one should have to type or “expose” a password.Die Veeam documentation refers to the option of copying the “configuration file” to other servers; however, you then have to reset the passwor
We are no longer able to use the "Update All" function on our Veeam Hardened Repository, as it fails with an error related to the GPG key.To clarify, we do not have a Host Management Web UI or a Veeam Appliance deployment. Our environment consists of Veeam Backup & Replication with a Linux Hardened Repository only.Username veeamsvc Cannot access log file directorytar -czf ~/veeamlog-$(date +%Y%m%d-%H%M%S).tar.gz /var/log/VeeamBackup/tar: Removing leading `/' from member namestar: /var/log/VeeamBackup: Cannot open: Permission deniedtar: Exiting with failure status due to previous errors Could you please advise on how to resolve the GPG key error in this configuration?
While trying to export.BAK file while using Veeam Explorer, it gives the following message what could be the issue. This same error appear by using instant recovery, recovering to the same location and alternate location, in addition to restore DB file to the same location and alternate location. DB Unable to attach database. | Subquery returned more than 1 value. This is not permitted when the subquery follows =, !=, <, <= , >, >= or when the subquery is used as an expression. | The statement has been terminated.
Version 13.0.1I am backing up to LTO 4 tape drives. I have one job that backs up drive M: and N: backups. One backup I get this error on drive M: and the next time on drive N:. 5/31/2026 7:27:36 AM Warning : Failed to create a VSS snapshot for M: Details: Writer 'MSMQ Writer (MSMQ)' is failed at 'VSS_WS_FAILED_AT_PREPARE_BACKUP'. The writer's timeout expired between the Freeze and Thaw events. --tr:Failed to verify writers state. --tr:Failed to create VSS snapshot. --tr:Failed to perform pre-backup tasks. (0:00:15)I changed the VSS timeout to 20 minutesI ran chkdsk and analyze and optimize on both drives. No errors. Windows 10 does it weekly. More than 50% available on both drives. I have rebooted the tape server. I restarted the services. The jobs are not big. M: is around 50GB. N: is 350GB. I never had this issue on 11A. Still get these errors.
when adding minIO object storage which is deployed on local server to vbr , it throws error of certificate reterival failed from minio..note:vbr is deployed using JeOS and is applinace based,minIO uses 2083 port for its api endpoint.do any one encounter this error and have wayout!
I'm experimenting with the VHR 2.0.09 ISO. It works perfectly for me. I'm using a virtual machine for VHR where I have two disks added, one for the OS and one for the repository. I'm trying to extend the repository. What would be the recommended steps to extend the disk, or is it not possible?
When I logged on to my Object First Appliance again, I saw that an update was available once more.Honestly, it’s almost too simple to write a blog post about, but why not ;-) Updating your Object First (Ootbi) appliance is super easy and quick (and much faster than it took to write this post).Updates roll out security patches, bug fixes, performance improvements, and new features — and the best part is that the whole thing is driven from a easy Web UI with only some clicks.In this post, I’ll walk you through updating your Ootbi cluster end to end: the online method (for internet-connected appliances), the offline method (for air-gapped or security-restricted environments), and the pre- and post-update checks I always recommend before calling the job done.Good to know: Ootbi updates are applied at the cluster level, not node by node. When you trigger an update, it’s automatically pushed across every node in the cluster, so all your nodes stay on the same version without any extra effort
Enhancement of NFS repository NFS repository is rely on NFS protocol, which is not built for heavy loads and using it should be used only, if another setup of repository is not possible.In my usecase is the only option, how to avoid connection of guests to repositories. NFS repository does not support fast cloning, so consumption is much higher like on repository with direct attached storage or object storage.Synthetic backup is taking very, very long for big VMs especially. How synthetic backup works with NFS repositoryDuring process gateway server needs to take files on gateway, where is data mover, create synthetic full backup and send it backup on nfs storage. How NFS repository works: they are mounting during backup/restore process in one threat and unmounted after backup/restore is done: Such configuration is very safe and is not visible nfs export during non-runtime. Based on my test one threat can run backups around 21MBps on 1Gbps line.In this case was distance was 50km and s
Hi everyone,just wanted to share something we hit recently after deploying Veeam B&R v13 in a Hyper-V environment.The issueAfter the upgrade, Application-Aware Processing stopped working.Symptoms:No Hyper-V production checkpoints Multiple VMs affected Happening across different customersWhat we checkedWe went through all the usual stuff:Firewall → OK Permissions → OK VSS → OK Integration services → OKEverything looked fine… but still no AAP.The causeAfter a long search, we found a post from mazvazzeg that pointed us in the right direction.Turns out it’s a wrong registry value for the Hyper-V VSS service (vmicvss).Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vmicvssWrong value in ImagePath: %systemroot%\system32\svchost.exe -k VeeamHvVssGroupstemNetworkRestrictedRedirectionGuard -pThis basically prevents the service from starting.The fixChange it to: %SystemRoot%\System32\svchost.exe -k VeeamHvVssGroup -pAfter that:Service starts correctly AAP works again Production ch
Scenario, a customer has a complex environment where their DC doesn’t have groups for servers, Laptops, Different users in different regions. Customer want to backup servers and endpoint but the laptop backup has different requirement. Let’s say Executive backup must backup the entire PC and other users you select a specific folder. If you deploy backup protection group using CSV files, there is a lot of manual requirements if changes happen to that environment. The question is how to use AD to create separate requirement even thou the DC is complex.
Today marks a big milestone as my fourth book was published - Mastering Veeam Backup & Replication v13. I wrote a blog about it when you can read in the link below, and I have put the links to Packt/Amazon where you can find it if interested. 😎This one was great to write, and I especially enjoyed the chapter on Veeam ONE that I put in this book. I would truly like to thank @Rick Vanover for his chapter contribution about the Console (Chapter 4) and also @NikolaPejkova for her inspiring Foreword that she wrote, it was very touching, and I am grateful.Blog - Mastering Veeam Backup & Replication v13 - BlogBook LinksPackt - Mastering Veeam Backup & Replication v13 - PacktAmazon - Mastering Veeam Backup & Replication v13 - Amazon
Ever wanted to chage your managed server from an IP Adress or DNS (shortname) to FQDN. Then you will find this article very useful. Since the move to version Veeam Backup & Replication (VBR) v13, we have seen that FQDN works more reliably in VBR/VSA due to strict reverse DNS requirements for certificate authentication, SSH, and agent deployment on Linux. IPs skip PTR lookups and often fail validation as demonstrated in this guide “Building VIHR: Ransomware-Proof Repository with Veeam JeOS“. In this article, we shall discuss how to “Switch from IP to DNS names for Backup Infrastructure in VBR cleanly”Managed Server Object RenamePrior to running the commands below you need to identify the IP\DNS (shortname) utilized by your Managed Server currently. Since I am currently using the hostname as Techda01 for example, and this could even be an IP address in your vase, this would need to be changed very shortly to a Fully Qualified Domain Name (FQDN). Note: Until now, this change cannot b
Hello Veeam Community! I'm excited to introduce a Python script that I've developed for anonymizing Veeam Backup & Replication logs. Protecting sensitive information in log files is crucial, and this script simplifies the process while maintaining the integrity of your logs. Veeam Log Anonymizer logo Acknowledgments:Before diving into the details, I'd like to express my gratitude:Bertrand: Thank you for the original idea that inspired this script and for your valuable improvement suggestions. Your input was instrumental in making this script more robust and feature-rich. Eric: A big thank you for your unwavering support and encouragement throughout the development process. Your feedback and insights helped shape this tool. Disclaimer:I want to clarify that I'm not a developer by profession, but rather a member of the Veeam community who saw the need for a tool like this. The script has been created out of a passion for data privacy and a desire to contribute to our community.Key Fe
Hello,I could say better late than never, i’m using a script since many years to make my configuration configuration immutable on a linux repos.Even it is now available for object storage and it will probably be immutable in future release, i think it could useful to share it. #!/bin/bash# Define a list of target directoriestarget_directories=("/path/to/your/target_directory1" "/path/to/your/target_directory2")attribute_to_apply=" +i" # The chattr attribute to apply (e.g., immutable)time_to_wait_days=10 # Time to wait in days before removing chattr attributelog_path="/path/to/your/logfile.log" # Replace with your desired log path# Calculate the time to wait in secondstime_to_wait_seconds=$((time_to_wait_days * 24 * 60 * 60))# Log the start timeecho "$(date): Chattr attribute application started for files in ${target_directories[*]}" >> $log_path# Loop through all target directoriesfor target_directory in "${target_directories[@]}"; do # Loop through all files in the target dir
Hello Veeam Community,This is a wrap for this month’s blog roundup!After some great entries and a close vote, we have a winner!Congratulations to our Blog of the Month winner, @Michael Melter with his blog SureBackup fails with “Invalid change tracker error code” on VMware VMs with VBS enabledAnd of course, well done to our finalists as well — it was a tough choice this time.If you didn’t win this round, keep sharing — your next post might be the one See you next month!Madi
OS is Linux Mint Mate 22. Been running VAL v.6 successfully for some time, now looking to update to v.13. File downloaded, only option seems to be .iso for which I use Balena Etcher. BE says, problem with this file, and cannot continue. Ran the download three times, BE tells me the same thing with each of the downloaded files.Previous Veeam downloads were .deb files, used for ubuntu/debian systems. Could be there isn’t or won’t be such for v.13. Anyone know whether v.12 is available?
Reflections from my MC2MC Rocket Talk – 21 May 2026 On 21 May 2026, I had the opportunity and privilege to speak at the MC2MC Community event, proudly sponsored by my company ORBID. During my rocket talk, I shared insights into a topic that is becoming increasingly critical for organizations operating in the cloud:How can we move beyond native Azure backup capabilities to achieve true data resilience?As more businesses migrate workloads to Microsoft Azure, protecting data is no longer just about creating backups—it is about ensuring business continuity, cyber resilience, and recovery flexibility. Why Data Protection Matters More Than EverThe session started with a reality check.Today's organizations face a growing number of threats and challenges:89% of ransomware attacks explicitly target backups. 33% of production workloads experienced unexpected outages last year. 82% of organizations cannot recover fast enough to meet business requirements. 82% cite a skills shortage as their num
Hello Team,I am using Veeam Agent / Veeam Backup and Replication for backup storage on a NAS.I noticed that in my backup repository folder, Veeam creates:.VBK full backup files multiple .VIB incremental backup files .VBM metadata filesMy question is:Why are there multiple .VBK files stored in the same backup folder?Are these incremental restore points expected behavior?Also:Will Veeam automatically delete old .VBK and .VIB files according to the retention policy? Is it safe to manually delete multiple or older .VBK files from the repository folder if storage becomes low? How does Veeam manage the backup chain cleanup process?I want to better understand how Veeam handles incremental backup retention and storage management.Thank you.
Hi everyone,I am delighted to present my first blog post and my first contribution to the Veeam community today. I would be very grateful for any feedback 😊 When working with Veeam Recovery Orchestrator (VRO), you might occasionally run into situations where the system makes decisions that aren’t immediately intuitive. Recently, a partner approached us with a scenario that raised exactly that kind of question: How does VRO choose which backup copy to use when multiple copies exist? Let’s walk through the use case, the unexpected behavior, and what we learned from digging into it. The Scenario In this environment, VRO is running at the disaster recovery site and orchestrating a vSphere-to-vSphere restore plan. The plan uses the following steps: A backup-to-disk job writes backups to a local backup repository. Immediately afterward, two backup copy jobs run in parallel to copy the backup data to two additional repositories — let’s call them Repository A and Repository B. The restor
Hello, On new V13 VSA installation, I would like to backup some VMs (inside domain) with AAIP enabled.When I try it as I did with V12, it doesn’t work. My VSA is not in a domain.I saw for authentication only Kerberos or certificates can be used (from Veeam deployment kit) because NTLM is removed.Does that mean I need to add my VBR server to the production domain if I don’t want to use Veeam deployment kit on all my Windows VMs ? I don’t find a way for my backup to work with AAIP enabled while I’m using domain\user account with correct privileges.I have this error : 29/05/2026 14:33:16 Failed : Failed to connect via Administrative share.Host: [COMPUTER.domain.com]. (Failed to connect to the guest OS. [Failed to connect to guest agent. Errors: 'Samba failed with error: NT_STATUS_NO_SUCH_DOMAIN [stderr: Kinit for administrateur@DOMAIN to access COMPUTER.domain.comfailed: Cannot find KDC for requested realm;Could not connect to server COMPUTER.domain.com;Connection failed: NT_STATUS_NO_SU
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.