<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Postgresql on Splunk Enterprise in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742381#M21937</link>
    <description>&lt;P&gt;Can't thank you enough! The Support ticket was on my todo list all day and kept getting back-burnered. Appreciate the information! Looking forward to rm'ing it in&amp;nbsp; the morning&lt;/P&gt;</description>
    <pubDate>Fri, 21 Mar 2025 03:09:43 GMT</pubDate>
    <dc:creator>SeanO_VA</dc:creator>
    <dc:date>2025-03-21T03:09:43Z</dc:date>
    <item>
      <title>Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742210#M21893</link>
      <description>&lt;P&gt;Splunk Enterprise ships with a copy of PostGreSQL. The latest splunk installer, v9.4.1, however still ships with a version of Postgresql 16.0 which has several Security vulnerabilities. Is there a documented way to upgrade the version to 16.7?&lt;BR /&gt;&lt;BR /&gt;Information on the PostgreSQL CVE&lt;BR /&gt;&lt;A href="https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/" target="_blank"&gt;https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 14:08:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742210#M21893</guid>
      <dc:creator>SeanO_VA</dc:creator>
      <dc:date>2025-03-19T14:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742216#M21894</link>
      <description>&lt;P&gt;Do not mess with software that ships with Splunk.&amp;nbsp; You may break something and/or lose support.&lt;/P&gt;&lt;P&gt;Open a support case or go to &lt;A href="https://ideas.splunk.com" target="_blank"&gt;https://ideas.splunk.com&lt;/A&gt; to report the vulnerabilities.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 14:23:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742216#M21894</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-19T14:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742218#M21895</link>
      <description>&lt;P&gt;Idea submitted, but with the attitude "Snapshots are our Friend", I'm willing to roll the dice if there's even an unsupported "how-To" out there&lt;BR /&gt;&lt;BR /&gt;Idea:&amp;nbsp;&lt;A href="https://ideas.splunk.com/ideas/EID-I-2527" target="_blank"&gt;https://ideas.splunk.com/ideas/EID-I-2527&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 14:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742218#M21895</guid>
      <dc:creator>SeanO_VA</dc:creator>
      <dc:date>2025-03-19T14:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742236#M21899</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308656"&gt;@SeanO_VA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would raise via support who will be able to instruct you of if/how you can safely remove postgres, however for what its worth - I havent yet found a feature of 9.4.x which requires the postgres to be configured/running - Is it running on your server?&lt;/P&gt;&lt;P&gt;If it isnt running then it isnt vulnerable to the SQL Injection of the referenced CVEs. It could be that future updates to Splunk require postgres for certain features, in which case I would hope that they've already updated Postgres &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fingers crossed it is updated for the next release.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 16:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742236#M21899</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-19T16:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742239#M21900</link>
      <description>There are coming some new features in future splunk versions which are using postgresql. Currently some of those are in beta/private preview phase, but I haven't heard that none of those are yet in use.&lt;BR /&gt;Are you sure that you have official version where you see PostgreSql?</description>
      <pubDate>Wed, 19 Mar 2025 16:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742239#M21900</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-03-19T16:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742249#M21901</link>
      <description>&lt;P&gt;I am assuming&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308656"&gt;@SeanO_VA&lt;/a&gt;&amp;nbsp;is referring to the postgres binaries (pg_* binaries - although may be more) in the $SPLUNK_HOME/bin directory - although for me none are running on my 9.4.1 instance.&lt;/P&gt;&lt;P&gt;In terms of uses in future version of Splunk etc, I suspect it will be highly likely that the patched versions would be included unless there is a good reason not to, at which point it would be time to discuss directly with Support/Account team to determine relevant mitigations.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 17:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742249#M21901</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-19T17:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742378#M21935</link>
      <description>&lt;P&gt;Just opened a ticket with support they said you can remove the file without problems and I have verified it, it was placed there as future versions are going to use it with patched version and will likely be removed with future versions of 9.14.x until that time.&amp;nbsp; I personally don't like that they are using it, since postgres gets updated all the time and thus having this dependency on your product.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 00:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742378#M21935</guid>
      <dc:creator>skurasak1</dc:creator>
      <dc:date>2025-03-21T00:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742381#M21937</link>
      <description>&lt;P&gt;Can't thank you enough! The Support ticket was on my todo list all day and kept getting back-burnered. Appreciate the information! Looking forward to rm'ing it in&amp;nbsp; the morning&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 03:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/742381#M21937</guid>
      <dc:creator>SeanO_VA</dc:creator>
      <dc:date>2025-03-21T03:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Postgresql on Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/745714#M22207</link>
      <description>&lt;P&gt;Agree 100%.&amp;nbsp; Hope they consider implementing a self-updating feature if they expect to have the frequency of updates that come along with postgresql.&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2025 16:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Postgresql-on-Splunk-Enterprise/m-p/745714#M22207</guid>
      <dc:creator>flakshack</dc:creator>
      <dc:date>2025-05-07T16:43:42Z</dc:date>
    </item>
  </channel>
</rss>

