How Veeam ONE alarm rules are built, linked and timed, and how severities are assigned.
From Ultra Transcenders VONE-13 by Tony Rough (coming January 2027)
Alarm rules define when an alarm fires, at what severity, and with which suppression behaviour. An alarm can hold up to 8 rules of different types.
| Rule type | Fires when | Example |
|---|---|---|
| Event-based rule | A hypervisor event or a Veeam Backup & Replication or Veeam Backup for Microsoft 365 event occurs | VmReconfiguredEvent on a given host; “Job exceeded backup window” |
| Specific condition or state | An object’s state or condition matches a value | Connection state not equal to Connected; job status equals Failed; repository free space below a threshold |
| Existing alarm | Another alarm triggers or changes status, after an optional delay | Raise a second alarm a set delay after a source alarm triggers |
| Resource usage counter | A performance counter is above or below a threshold | Datastore usage, CPU usage, CDP proxy cache usage |
The available condition and state rules depend on the alarm type. For backup objects they include, among others, Job/Policy status, Backup Copy RPO, Cloud instance RPO, Incremental backup size, Disabled job, Data collection consistency, Job duration exceeded the allowed time period, Unusual job duration, Backup security and compliance, Disabled malware detection, Potential malware activity, Immutability state, Out-of-date state, Repository server is running out of free space (absolute or relative threshold) and CDP Proxy Cache Usage. For Veeam Backup for Microsoft 365 they include Organization without backups, Restore activity and Maintenance mode. VM alarms include “VMs with no restore points” and “Orphaned Veeam Backup & Replication snapshot”.
| Setting | Effect |
|---|---|
| Event name | The event that triggers the alarm. vSphere events are entered without the prefix: VmReconfiguredEvent, not vim.event.VmReconfiguredEvent |
| Event text | Keywords the event description must contain (a user, object or action) |
| Wildcards | * matches zero or more characters and ? one character, in both fields |
| Ignore after | Number of times the alarm fires for the same event or condition before further repeats are suppressed until the alarm is resolved; 0 means fire every time |
| Trigger after | Number of times the event must repeat before the alarm fires; default 0 (fire on the first occurrence) |
Counter-based rules compare data collected over a period with a threshold, and the aggregation type decides how strict that comparison is.
| Aggregation | Condition Above | Condition Below |
|---|---|---|
| Min | Fires only if all values are above the threshold | Fires if at least one value is below |
| Avg | Fires if the average is above | Fires if the average is below |
| Max | Fires if at least one value is above | Fires only if all values are below |
Some rules use Analysis depth instead: the number of latest values used to compute an average, against which each new value is compared. Counter rules apply to all storage objects in scope (a host datastore usage rule covers every datastore on the host) unless names are listed in Exclude instances, separated by semicolons; drives are written with a backslash, such as C:\.
By default, an alarm with several rules fires when any one rule’s condition is met. Rules can be linked with Boolean operators:
Rules can also be built from existing data. From the Tasks & Events tab, right-click an event and choose Create new alarm (adds an event-based rule) or Add this event to the existing alarm. From a performance chart, right-click a counter and choose Create new alarm or Add this counter to the existing alarm (not available for objects without performance data, such as datacenters and clusters). From the Processes or Services tab of a VM, Create Alarm builds a state-based rule.
Common trap: Choosing Max with “Above” to avoid noise - Max fires if any single sample is above the threshold, which is the most sensitive option; Min with “Above” fires only when every sample is above it.
Common trap: Expecting two rules on one alarm to require both conditions - unlinked rules behave as OR; link them with AND, and remember only adjacent rules can be linked.
This note is one section of Ultra Transcenders VONE-13: Veeam ONE 13, an independent study guide that explains every topic the course covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to the Veeam Help Center.
Due on Amazon in January 2027, in Kindle and paperback editions.
About the book · VONE-13 terms in the glossary · All VONE-13 study notes
Which Veeam ONE tasks belong in the Windows Client and which in the browser-based Web Client.
Suppression, silence mode, summary notifications and rule timing to cut unwanted Veeam ONE alerts.
Single-parameter, multiple-condition, grouping expression, import or manual: which Business View method fits.
Which Veeam ONE reports use the new v13 engine and which still use the legacy engine and SSRS.