Kaspersky Industrial CyberSecurity for Networks

Folders for storing application data

March 22, 2024

ID 111267

Deleting or modifying any file in these folders can affect the operation of the application.

On the Kaspersky Industrial CyberSecurity for Networks Server, the application uses the following folders and subfolders for storing data:

  • Component and service installation folders:
    • /opt/kaspersky/kics4net/ – for the Server.
    • /opt/kaspersky/kics4net-apm/ – for the active polling connector.
    • /opt/kaspersky/kics4net-asset-inventory/ – for the service that processes the results of scanning device attributes using OVAL rules.
    • /opt/kaspersky/kics4net-blob-storage/ – for the service that stores arrays of binary data. (Binary Large Object, BLOB).
    • /opt/kaspersky/kics4net-connectors/ – for system connectors.
    • /opt/kaspersky/kics4net-connectors-launcher/ – for the service of registering and launching manageable connectors.
    • /opt/kaspersky/kics4net-email-gateway/ – for the service of sending email notifications.
    • /opt/kaspersky/kics4net-epp-proxy/ – for the Kaspersky Endpoint Agent integration service.
    • /opt/kaspersky/kics4net-fts/ – for the full-text search system.
    • /opt/kaspersky/kics4net-nats-server/ – for the message broker.
    • /opt/kaspersky/kics4net-oval-facade/ – for the service that performs remote device scanning using OVAL rules.
    • /opt/kaspersky/kics4net-postgresql/ – for the DBMS.
    • /opt/kaspersky/kics4net-report-builder/ – for the service of generating reports.
    • /opt/kaspersky/kics4net-report-data-source/ – for the service of providing data for reports.
    • /opt/kaspersky/kics4net-report-renderer/ – for the service of visual representation of data blocks in reports.
    • /opt/kaspersky/kics4net-report-templates-catalog/ – for the service of managing report templates.
    • /opt/kaspersky/kics4net-report-templates-catalog-view/ – for the service of providing data on report templates.
    • /opt/kaspersky/kics4net-task-manager/ – for the response task management service.
    • /opt/kaspersky/kics4net-risk-oval-detector/ – for the service for processing the results of the device scan for risks using the OVAL rules.
    • /opt/kaspersky/kics4net-scan-oval-manager/ – for the service for managing the device scan using OVAL rules.
    • /opt/kaspersky/kics4net-scap-manager/ – for the security audit management service.
    • /opt/kaspersky/kics4net-scap-manager-view/ – for the service that provides data on security audit.
    • /opt/kaspersky/kics4net-scheduler/ – for the task scheduling service.
    • /opt/kaspersky/kics4net-secrets/ – for the secrets repository facade.
    • /opt/kaspersky/kics4net-suricata/ – for the Intrusion Detection system.
    • /opt/kaspersky/kics4net-task-manager/ – for the task management service.
    • /opt/kaspersky/kics4net-task-manager-view/ – for the service of providing data on tasks.
    • /opt/kaspersky/kics4net-vault/ – for the service for storing the secrets in the repository.
    • /opt/kaspersky/kics4net-webserver/ – for the web server.
    • /opt/kaspersky/klnagent64/ – for Network Agent.
  • Folders for storing certificates and operational data:
    • /opt/kaspersky/kics4net/share/ids/ – for the Intrusion Detection system.
    • /var/opt/kaspersky/kics4net/ – for the Server.
    • /var/opt/kaspersky/kics4net-apm/ – for the active polling connector.
    • /var/opt/kaspersky/kics4net-asset-inventory/ – for the service of processing the results of the device attribute scan using the OVAL rules.
    • /var/opt/kaspersky/kics4net-blob-storage/ – for the BLOB service.
    • /var/opt/kaspersky/kics4net-connectors/ – for system connectors.
    • /var/opt/kaspersky/kics4net-connectors-launcher/ – for the service of registering and launching manageable connectors.
    • /var/opt/kaspersky/kics4net-email-gateway/ – for the service of sending email notifications.
    • /var/opt/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /var/opt/kaspersky/kics4net-fts/ – for the full-text search system.
    • /var/opt/kaspersky/kics4net-nats-server/ – for the message broker.
    • /var/opt/kaspersky/kics4net-oval-facade/ – for the service for scanning remote devices using OVAL rules.
    • /var/opt/kaspersky/kics4net-postgresql/ – for the DBMS.
    • /var/opt/kaspersky/kics4net-report-builder/ – for the service of generating reports.
    • /var/opt/kaspersky/kics4net-report-data-source/ – for the service of providing data for reports.
    • /var/opt/kaspersky/kics4net-report-renderer/ – for the service of presenting data blocks in reports.
    • /var/opt/kaspersky/kics4net-report-templates-catalog/ – for the service of managing report templates.
    • /var/opt/kaspersky/kics4net-report-templates-catalog-view/ – for the service of providing data on report templates.
    • /var/opt/kaspersky/kics4net-responses-manager/ – for the response task management service.
    • /var/opt/kaspersky/kics4net-risk-oval-detector/ – for the service of processing the results of the device scan for risks using the OVAL rules.
    • /var/opt/kaspersky/kics4net-scan-oval-manager/ – for the service for managing the device scan using OVAL rules.
    • /var/opt/kaspersky/kics4net-scap-manager/ – for the security audit management service.
    • /var/opt/kaspersky/kics4net-scap-manager-view/ – for the service that provides data on security audit.
    • /var/opt/kaspersky/kics4net-scheduler/ – for the task scheduling service.
    • /var/opt/kaspersky/kics4net-task-manager/ – for the task management service.
    • /var/opt/kaspersky/kics4net-task-manager-view/ – for the service of providing data on tasks.
    • /var/opt/kaspersky/kics4net-vault/ – for the service for storing the secrets in the repository.
    • /var/opt/kaspersky/kics4net-webserver/ – for the web server.
    • /var/opt/kaspersky/klnagent/ – for Network Agent.
  • Folders for storing process logs:
    • /home/<user>/.config/kaspersky/kics4net-deploy/ – folder for storing installation process logs and the installation settings file (if application components were centrally installed from this computer).
    • /var/log/kaspersky/kics4net/ – for the Server.
    • /var/log/kaspersky/kics4net-apm/ – for the active polling connector.
    • /var/log/kaspersky/kics4net-asset-inventory/ – for the service of processing the results of the device attribute scan using the OVAL rules.
    • /var/log/kaspersky/kics4net-blob-storage/ – for the BLOB service.
    • /var/log/kaspersky/kics4net-connectors/ – for system connectors.
    • /var/log/kaspersky/kics4net-connectors-launcher/ – for the service of registering and launching manageable connectors.
    • /var/log/kaspersky/kics4net-email-gateway/ – for the service of sending email notifications.
    • /var/log/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /var/log/kaspersky/kics4net-fts/ – for the full-text search system.
    • /var/log/kaspersky/kics4net-nats-server/ – for the message broker.
    • /var/log/kaspersky/kics4net-oval-facade/ – for the service that performs remote device scanning using OVAL rules.
    • /var/log/kaspersky/kics4net-postgresql/ – for the DBMS.
    • /var/log/kaspersky/kics4net-report-builder/ – for the service of generating reports.
    • /var/log/kaspersky/kics4net-report-data-source/ – for the service of providing data for reports.
    • /var/log/kaspersky/kics4net-report-renderer/ – for the service of presenting data blocks in reports.
    • /var/log/kaspersky/kics4net-report-templates-catalog/ – for the service of managing report templates.
    • /var/log/kaspersky/kics4net-report-templates-catalog-view/ – for the service of providing data on report templates.
    • /var/log/kaspersky/kics4net-responses-manager/ – for the response task management service.
    • /var/log/kaspersky/kics4net-risk-oval-detector/ – for the service of processing the results of the device scan for risks using the OVAL rules.
    • /var/log/kaspersky/kics4net-scan-oval-manager/ – for the service for managing the device scan using OVAL rules.
    • /var/log/kaspersky/kics4net-scap-manager/ – for the security audit management service.
    • /var/log/kaspersky/kics4net-scap-manager-view/ – for the service that provides data on security audit.
    • /var/log/kaspersky/kics4net-scheduler/ – for the task scheduling service.
    • /var/log/kaspersky/kics4net-secrets/ – for the secrets repository facade.
    • /var/log/kaspersky/kics4net-suricata/ – for the Intrusion Detection system.
    • /var/log/kaspersky/kics4net-task-manager/ – for the task management service.
    • /var/log/kaspersky/kics4net-task-manager-view/ – for the service of providing data on tasks.
    • /var/log/kaspersky/kics4net-vault/ – for the service for storing the secrets in the repository.
    • /var/log/kaspersky/kics4net-webserver/ – for the web server (the web server also saves process data in the system log of the operating system).
    • /var/log/kaspersky/klnagent64/ – for Network Agent.
  • Folders for storing configuration files:
    • /etc/opt/kaspersky/kics4net/ – for the Server.
    • /etc/opt/kaspersky/kics4net-asset-inventory/ – for the service of processing the results of the device attribute scan using the OVAL rules.
    • /etc/opt/kaspersky/kics4net-blob-storage/ – for the BLOB service.
    • /etc/opt/kaspersky/kics4net-email-gateway/ – for the service of sending email notifications.
    • /etc/opt/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /etc/opt/kaspersky/kics4net-fts/ – for the full-text search system.
    • /etc/opt/kaspersky/kics4net-nats-server/ – for the message broker.
    • /etc/opt/kaspersky/kics4net-oval-facade/ – for the service that performs remote device scanning using OVAL rules.
    • /etc/opt/kaspersky/kics4net-report-builder/ – for the service of generating reports.
    • /etc/opt/kaspersky/kics4net-report-data-source/ – for the service of providing data for reports.
    • /etc/opt/kaspersky/kics4net-report-renderer/ – for the service of presenting data blocks in reports.
    • /etc/opt/kaspersky/kics4net-report-templates-catalog/ – for the service of managing report templates.
    • /etc/opt/kaspersky/kics4net-report-templates-catalog-view/ – for the service of providing data on report templates.
    • /etc/opt/kaspersky/kics4net-responses-manager/ – for the response task management service.
    • /etc/opt/kaspersky/kics4net-risk-oval-detector/ – for the service of processing the results of the device scan for risks using the OVAL rules.
    • /etc/opt/kaspersky/kics4net-scan-oval-manager/ – for the service for managing the device scan using OVAL rules.
    • /etc/opt/kaspersky/kics4net-scap-manager/ – for the security audit management service.
    • /etc/opt/kaspersky/kics4net-scap-manager-view/ – for the service that provides data on security audit.
    • /etc/opt/kaspersky/kics4net-scheduler/ – for the task scheduling service.
    • /etc/opt/kaspersky/kics4net-secrets/ – for the secrets repository facade.
    • /etc/opt/kaspersky/kics4net-task-manager/ – for the task management service.
    • /etc/opt/kaspersky/kics4net-task-manager-view/ – for the service of providing data on tasks.
    • /etc/opt/kaspersky/kics4net-vault/ – for the service for storing the secrets in the repository.
    • /etc/opt/kaspersky/kics4net-webserver/ – for the web server.
    • /etc/opt/kaspersky/klnagent/ – for Network Agent.
    • /usr/lib/systemd/system/ – for storing configuration files for Kaspersky Industrial CyberSecurity for Networks services (for example, kics4net.service).
    • /var/opt/kaspersky/kics4net-deploy/ – folder for storing a copy of the installation settings file created during centralized installation of the application.
    • /var/run/ – for storing variables of data on system health after loading in the folder itself (for example, the klnagent.pid file), or in subfolders (for example, the /kics4net/ subfolder).

On the Kaspersky Industrial CyberSecurity for Networks sensor, the application uses the following folders and subfolders for storing data:

  • Component and service installation folders:
    • /opt/kaspersky/kics4net/ – for the sensor.
    • /opt/kaspersky/kics4net-apm/ – for the active polling connector.
    • /opt/kaspersky/kics4net-connectors/ – for system connectors.
    • /opt/kaspersky/kics4net-connectors-launcher/ – for the service of registering and launching manageable connectors.
    • /opt/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /opt/kaspersky/kics4net-nats-server/ – for the message broker.
    • /opt/kaspersky/kics4net-oval-facade/ – for the service that performs remote device scanning using OVAL rules
    • /opt/kaspersky/kics4net-suricata/ – for the Intrusion Detection system.
    • /opt/kaspersky/kics4net-websensor/ – for the web server.
  • Folders for storing certificates and operational data:
    • /opt/kaspersky/kics4net/share/ids/ – for the Intrusion Detection system.
    • /var/opt/kaspersky/kics4net/ – for the sensor.
    • /var/opt/kaspersky/kics4net-apm/ – for the active polling connector.
    • /var/opt/kaspersky/kics4net-connectors/ – for system connectors.
    • /var/opt/kaspersky/kics4net-connectors-launcher/ – for the service of registering and launching manageable connectors.
    • /var/opt/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /var/opt/kaspersky/kics4net-nats-server/ – for the message broker.
    • /var/opt/kaspersky/kics4net-oval-facade/ – for the device scan service using OVAL rules without the Network Agent.
    • /var/opt/kaspersky/kics4net-websensor/ – for the web server.
  • Folders for storing process logs:
    • /home/<user>/.config/kaspersky/kics4net-deploy/ – folder for storing installation process logs and the installation settings file (if application components were centrally installed from this computer).
    • /var/log/kaspersky/kics4net/ – for the sensor.
    • /var/log/kaspersky/kics4net-apm/ – for the active polling connector.
    • /var/log/kaspersky/kics4net-connectors/ – for system connectors.
    • /var/log/kaspersky/kics4net-connectors-launcher/ – for the service of registering and launching manageable connectors.
    • /var/log/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /var/log/kaspersky/kics4net-nats-server/ – for the message broker.
    • /var/log/kaspersky/kics4net-oval-facade/ – for the service that performs remote device scanning using OVAL rules
    • /var/log/kaspersky/kics4net-suricata/ – for the Intrusion Detection system.
    • /var/log/kaspersky/kics4net-websensor/ – for the web server (the web server also saves process data in the system log of the operating system).
  • Folders for storing configuration files:
    • /etc/opt/kaspersky/kics4net/ – for the sensor.
    • /etc/opt/kaspersky/kics4net-epp-proxy/ – for the integration service.
    • /etc/opt/kaspersky/kics4net-nats-server/ – for the message broker.
    • /etc/opt/kaspersky/kics4net-oval-facade/ – for the service that performs remote device scanning using OVAL rules
    • /etc/opt/kaspersky/kics4net-websensor/ – for the web server.
    • /etc/opt/kaspersky/klnagent/ – for Network Agent.
    • /usr/lib/systemd/system/ – for storing configuration files for Kaspersky Industrial CyberSecurity for Networks services (for example, kics4net.service).
    • /var/opt/kaspersky/kics4net-deploy/ – folder for storing a copy of the installation settings file created during centralized installation of the application.
    • /var/run/ – for storing variables of data on system health after loading in the folder itself or in subfolders.

Root privileges in the operating system are required for modifying the application files.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.