Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tmwbI-000Ro9-6Q for pgsql-general@arkaria.postgresql.org; Tue, 25 Feb 2025 15:12:00 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tmwbG-003YX8-PB for pgsql-general@arkaria.postgresql.org; Tue, 25 Feb 2025 15:11:58 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tmwbG-003YWR-DI for pgsql-general@lists.postgresql.org; Tue, 25 Feb 2025 15:11:58 +0000 Received: from fhigh-a7-smtp.messagingengine.com ([103.168.172.158]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1tmwbD-0001B3-1a for pgsql-general@postgresql.org; Tue, 25 Feb 2025 15:11:57 +0000 Received: from phl-compute-09.internal (phl-compute-09.phl.internal [10.202.2.49]) by mailfhigh.phl.internal (Postfix) with ESMTP id E24E311400D3; Tue, 25 Feb 2025 10:11:55 -0500 (EST) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-09.internal (MEProxy); Tue, 25 Feb 2025 10:11:55 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aklaver.com; h= cc:content-transfer-encoding:content-type:content-type:date:date :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm3; t=1740496315; x=1740582715; bh=5YCB8cuW3ol9dd0JbBYcDc7eUzpYvOi+meEVa4bA+do=; b= QBWhE6icHrsjvoz5oumhmv3OF2emXprYgClj2frNabWXAddVgAjbAQR0H3f5WFrv 0zJIGrrdjEI9ig8Q2QrDiXCs8bTmoYQUsrxCVDdW6MCWAYisAV4KnHNZTHuaqyYu zDqnLc/5opuwRwvGLr/iaN978BnECfjvrvQBAvWTcsOzDzyqvpS/NlifMQzlpI9M 5NRKhDumk8GmZ9+wCfrK86wDfI8q/II9NF4saoiBU5P0vyYsviYA9rDPNmtBbWLZ /KX0Lu4FyW2jR4kEK+86QQ9hCrmJk71t8R66IAHCAnIdKhBU4lpcS4PXAKE8Vddw 5pwx/QNYzcyJwHmqGPGjuQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm1; t=1740496315; x=1740582715; bh=5 YCB8cuW3ol9dd0JbBYcDc7eUzpYvOi+meEVa4bA+do=; b=3WfNxfT/MxlXfcg2+ ZgKN1ZLYC+1S0XpGfjQJghd6mtYICtcCoq3pdad+0Boowj76+vjUxM0LmCtQ2ARW EbjXwXtE81OS2Pshm46NnnmnnWo7hk2pa1ZB96vzen3MFL7f+1JhEHnLbNOwq3XG Lr+LOSOkc+tY0pOTe2DLLQVJ070evZA2lmOtoEsRen6pAR48xlM4akfpM5fSRjuZ sTOSjI090fgwlwHgI6jtDWypH29nMn6s6g0XU6PYwoXcZ8JH6Hhh60D3YnTMZDO7 lawBRobHy806zSMQlFRZ457eh3t3b+oDAr9VQHNFsCUcOIBtLVJj4evGcn/botvO pkY3Q== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgdekvddtvdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivg hnthhsucdlqddutddtmdenucfjughrpefkffggfgfuvfhfhfgjtgfgsehtjeertddtvdej necuhfhrohhmpeetughrihgrnhcumfhlrghvvghruceorggurhhirghnrdhklhgrvhgvrh esrghklhgrvhgvrhdrtghomheqnecuggftrfgrthhtvghrnhepkeefheduvdejiefgieef jedtudduffelvdefleehfedtieffuefgvdekleegtddvnecuffhomhgrihhnpehpohhsth hgrhgvshhqlhdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgr ihhlfhhrohhmpegrughrihgrnhdrkhhlrghvvghrsegrkhhlrghvvghrrdgtohhmpdhnsg gprhgtphhtthhopedvpdhmohguvgepshhmthhpohhuthdprhgtphhtthhopehsrghkshhh ihdrsggvhhhlsegtrhgvughothhsrdgtohhmpdhrtghpthhtohepphhgshhqlhdqghgvnh gvrhgrlhesphhoshhtghhrvghsqhhlrdhorhhg X-ME-Proxy: Feedback-ID: i76984098:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 25 Feb 2025 10:11:55 -0500 (EST) Message-ID: Date: Tue, 25 Feb 2025 07:11:54 -0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: PgSQL - SIEM Integration To: Sakshi Behl , "pgsql-general@postgresql.org" References: Content-Language: en-US From: Adrian Klaver In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On 2/24/25 22:51, Sakshi Behl wrote: > Hi Team, > > We are in the process of integrating pgSQL with our SIEM and would > appreciate your expert guidance on this matter. > Kindly refer to the attached document outlining the events of interest > and provide your input based on the relevant postgreSQL log entries. https://www.postgresql.org/docs/current/event-trigger-definition.html > > Looking forward to hearing from you. > > Thanks -- Adrian Klaver adrian.klaver@aklaver.com