FREE STUDY NOTES · VONE-13

Veeam ONE alarm rules, severities and conditions

How Veeam ONE alarm rules are built, linked and timed, and how severities are assigned.

From Ultra Transcenders VONE-13 by Tony Rough (coming January 2027)

Alarm rules define when an alarm fires, at what severity, and with which suppression behaviour. An alarm can hold up to 8 rules of different types.

Rule types

Rule type Fires when Example
Event-based rule A hypervisor event or a Veeam Backup & Replication or Veeam Backup for Microsoft 365 event occurs VmReconfiguredEvent on a given host; “Job exceeded backup window”
Specific condition or state An object’s state or condition matches a value Connection state not equal to Connected; job status equals Failed; repository free space below a threshold
Existing alarm Another alarm triggers or changes status, after an optional delay Raise a second alarm a set delay after a source alarm triggers
Resource usage counter A performance counter is above or below a threshold Datastore usage, CPU usage, CDP proxy cache usage

The available condition and state rules depend on the alarm type. For backup objects they include, among others, Job/Policy status, Backup Copy RPO, Cloud instance RPO, Incremental backup size, Disabled job, Data collection consistency, Job duration exceeded the allowed time period, Unusual job duration, Backup security and compliance, Disabled malware detection, Potential malware activity, Immutability state, Out-of-date state, Repository server is running out of free space (absolute or relative threshold) and CDP Proxy Cache Usage. For Veeam Backup for Microsoft 365 they include Organization without backups, Restore activity and Maintenance mode. VM alarms include “VMs with no restore points” and “Orphaned Veeam Backup & Replication snapshot”.

Event-based rule settings

Setting Effect
Event name The event that triggers the alarm. vSphere events are entered without the prefix: VmReconfiguredEvent, not vim.event.VmReconfiguredEvent
Event text Keywords the event description must contain (a user, object or action)
Wildcards * matches zero or more characters and ? one character, in both fields
Ignore after Number of times the alarm fires for the same event or condition before further repeats are suppressed until the alarm is resolved; 0 means fire every time
Trigger after Number of times the event must repeat before the alarm fires; default 0 (fire on the first occurrence)

Resource usage rules: aggregation and analysis depth

Counter-based rules compare data collected over a period with a threshold, and the aggregation type decides how strict that comparison is.

Aggregation Condition Above Condition Below
Min Fires only if all values are above the threshold Fires if at least one value is below
Avg Fires if the average is above Fires if the average is below
Max Fires if at least one value is above Fires only if all values are below

Some rules use Analysis depth instead: the number of latest values used to compute an average, against which each new value is compared. Counter rules apply to all storage objects in scope (a host datastore usage rule covers every datastore on the host) unless names are listed in Exclude instances, separated by semicolons; drives are written with a backslash, such as C:\.

Linking rules

By default, an alarm with several rules fires when any one rule’s condition is met. Rules can be linked with Boolean operators:

Building rules from what you see

Rules can also be built from existing data. From the Tasks & Events tab, right-click an event and choose Create new alarm (adds an event-based rule) or Add this event to the existing alarm. From a performance chart, right-click a counter and choose Create new alarm or Add this counter to the existing alarm (not available for objects without performance data, such as datacenters and clusters). From the Processes or Services tab of a VM, Create Alarm builds a state-based rule.

Common trap: Choosing Max with “Above” to avoid noise - Max fires if any single sample is above the threshold, which is the most sensitive option; Min with “Above” fires only when every sample is above it.

Common trap: Expecting two rules on one alarm to require both conditions - unlinked rules behave as OR; link them with AND, and remember only adjacent rules can be linked.

Get the whole book

This note is one section of Ultra Transcenders VONE-13: Veeam ONE 13, an independent study guide that explains every topic the course covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to the Veeam Help Center.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in January 2027, in Kindle and paperback editions.

About the book · VONE-13 terms in the glossary · All VONE-13 study notes

More VONE-13 study notes