<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to upgrade OpenSSL on Splunk servers? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756563#M23596</link>
    <description>&lt;P&gt;We have this Tenable vulnerability on some of our Splunk servers -&lt;A href="https://www.tenable.com/plugins/nessus/266318" target="_self"&gt;&amp;nbsp;https://www.tenable.com/plugins/nessus/266318&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And the solution specified is - "&lt;SPAN&gt;Upgrade to OpenSSL version 1.0.2zm or later." We are running Splunk on-prem 9.3.3, and we wonder, what would be the correct way to upgrade OpenSSL with Splunk running?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I ran the following two commands, and I see different versions -&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$openssl version&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;OpenSSL 1.1.1k FIPS 25 Mar 2021&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$./splunk cmd openssl version&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OpenSSL 1.0.2zk-fips 3 Sep 2024&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Dec 2025 17:40:44 GMT</pubDate>
    <dc:creator>danielbb</dc:creator>
    <dc:date>2025-12-16T17:40:44Z</dc:date>
    <item>
      <title>How to upgrade OpenSSL on Splunk servers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756563#M23596</link>
      <description>&lt;P&gt;We have this Tenable vulnerability on some of our Splunk servers -&lt;A href="https://www.tenable.com/plugins/nessus/266318" target="_self"&gt;&amp;nbsp;https://www.tenable.com/plugins/nessus/266318&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And the solution specified is - "&lt;SPAN&gt;Upgrade to OpenSSL version 1.0.2zm or later." We are running Splunk on-prem 9.3.3, and we wonder, what would be the correct way to upgrade OpenSSL with Splunk running?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I ran the following two commands, and I see different versions -&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$openssl version&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;OpenSSL 1.1.1k FIPS 25 Mar 2021&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$./splunk cmd openssl version&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OpenSSL 1.0.2zk-fips 3 Sep 2024&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 17:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756563#M23596</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-12-16T17:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade OpenSSL on Splunk servers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756564#M23597</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196884"&gt;@danielbb&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You cannot/shouldnt upgrade individual components of the packaged Splunk service as this risks breaking things and is not supported.&amp;nbsp;&lt;/P&gt;&lt;P&gt;An updated OpenSSL binary is likely in an upcoming version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the meantime I would raise this with your Splunk account team and take other mitigations where possible.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 18:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756564#M23597</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-12-16T18:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to upgrade OpenSSL on Splunk servers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756565#M23598</link>
      <description>&lt;P&gt;I'm sorry but has anyone of your "vulnerability management" team actually read the description of this "finding"? Has anyone bothered to ask what this is about and is there even a remote chance that the "vulnerable" functionality is used anywhere in your Splunk environment? Hey, has anyone bothered to even verify the finding instead of relying on the banner and assuming the library didn't get a backported fix? (relatively unprobable but still possible).&lt;/P&gt;&lt;P&gt;Or is it just "oh, something's not green, let's make it all green!" approach?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 19:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-upgrade-OpenSSL-on-Splunk-servers/m-p/756565#M23598</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-12-16T19:54:23Z</dc:date>
    </item>
  </channel>
</rss>

