Files
splunk-security_content/macros/ollama_server.yml
Rod Soto 0bcb54b6f9 Ollama TA detections (#3710)
* commit1oll

* olldet2

* olldet3

* fixeddet3

* fixsp

* olldet4

* olldet5

* detoll6

* olldet7

* olldet8

* datasets

* testfixes

* modifiedtasearch

* lotsofixes

* fixednewta

* addedmorerefs

* fixedatasource

* fixedthreatobject

* fixedetectionandalertmessage

* fixedalermessage

* fixedquotes

* fixedhowtoimp

* fixeddescriptionandhowto

* changedestforuripat

* fixedowasplink

* Update detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/application/ollama_possible_rce_via_model_loading.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* protoexnassuggestions

* mionr

* remove index=*

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 21:54:37 +02:00

4 lines
225 B
YAML

definition: (sourcetype="ollama:server")
description: Customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
name: ollama_server