Skip to main content

LFD - Suspicious process running under user postgres

Comments

7 comments

  • cPRex Jurassic Moderator
    Hey there! When PostGreSQL is installed with the "/scripts/installpostgres" command that currently installs version 9, so cPanel would not be creating anything in /usr/pgsql-10/bin/postgres. If you have manually installed a newer version of PostGreSQL on the machine, that would explain that file path. If you did perform a manual installation, and are using PostGreSQL on the server, it's possible that CSF could have flagged that process and you just need to add it to the LFD ignore list.
    0
  • eventtex
    Hey there! When PostGreSQL is installed with the "/scripts/installpostgres" command that currently installs version 9, so cPanel would not be creating anything in /usr/pgsql-10/bin/postgres. If you have manually installed a newer version of PostGreSQL on the machine, that would explain that file path. If you did perform a manual installation, and are using PostGreSQL on the server, it's possible that CSF could have flagged that process and you just need to add it to the LFD ignore list.

    Hello, Thank you for your reply. In the CSF settings at WHM level I edited the file /etc/csf/csf.ignore by adding the following line: exe:/usr/pgsql-10/bin/postgres However, I always receive the same type of email. Can you tell me if the syntax of the line I added is correct? Thank you for your reply.
    0
  • cPRex Jurassic Moderator
    That looks correct to me. If that isn't working how you expect, it would be best to reach out to the ConfigServer support team at Technical Support as cPanel doesn't develop this application.
    0
  • eventtex
    That looks correct to me. If that isn't working how you expect, it would be best to reach out to the ConfigServer support team at
    0
  • cPRex Jurassic Moderator
    Let me know if you need anything else from our end!
    0
  • eventtex
    Let me know if you need anything else from our end!

    I think I found where the problem was. I had added the line in the csf.ignore file when it was the csf.pignore file that needed to be modified. Until now I no longer receive alert notifications.
    0
  • cPRex Jurassic Moderator
    Thanks for posting that clarification!
    0

Please sign in to leave a comment.