Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

DirectoryStructure

doug edited this page Aug 27, 2019 · 4 revisions

Please note! This wiki is no longer maintained. Our documentation has moved to https://securityonion.net/docs/. Please update your bookmarks. You can find the latest version of this page at: https://securityonion.net/docs/DirectoryStructure.

/nsm Directory Structure

/nsm

Backup, Bro, sensor (if configured as sensor), and server (if configured as server) data.

/nsm/bro

Bro IDS logs.

/nsm/elsa

ELSA data.

/nsm/sensor_data

Sensor data including argus, IDS alerts, and full pcap organized by sensor name ($HOSTNAME-$INTERFACE).

/nsm/server_data

Server data including IDS rulesets.

Clone this wiki locally