Directory Structure


Applications read their configuration from /opt/so/conf/. However, please keep in mind that most config files are managed with Salt, so if you manually modify those config files, your changes may be overwritten at the next Salt update.


Debug logs are stored in /opt/so/log/.


ElastAlert 2 and Suricata rules are stored in /opt/so/rules/.


Custom Salt settings can be added to /opt/so/saltstack/local/.


The vast majority of data is stored in /nsm/.


Zeek writes its protocol logs to /nsm/zeek/.


Elasticsearch stores its data in /nsm/elasticsearch/.


Stenographer stores full packet capture in /nsm/pcap/.


Suricata stores full packet capture in /nsm/pcap/.