Default file locations

Neo4j directories

The page describes the Neo4j directories, specifying their default locations per distribution and minimal file permissions.

If Neo4j was installed using a tar.gz or zip archive, <NEO4J_HOME> refers to the location the archive was extracted to.

Instructions provided for Neo4j Desktop are applicable across all operating systems where Neo4j Desktop is supported.

If tmp is set to noexec, it is recommended to set server.jvm.additional=-Djava.io.tmpdir=/home/neo4j in conf/neo4j.conf and replace /home/neo4j with a path that has exec permissions.

For /bin/cypher-shell, set this via an environment variable: export JAVA_OPTS=-Djava.io.tmpdir=/home/neo4j and replace /home/neo4j with a path that has exec permissions.

For the Neo4j’s uses of the Java Native Access (JNA) library, set server.jvm.additional=-Djna.tmpdir=/tmp in conf/neo4j.conf and replace /tmp with a path that has exec permissions.

Bin

The bin directory contains the Neo4j running script and built-in tools, such as Cypher Shell and Neo4j Admin and Neo4j CLI.

File permissions

Read only and execute.

Table 1. bin directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/bin

Windows

<NEO4J_HOME>\bin

Debian / RPM

/usr/bin

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal and run cd bin.

Certificates

The certificate directory contains the Neo4j TLS certificates.

File permissions

Read only.

Table 2. certificates directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/certificates

Windows

<NEO4J_HOME>\certificates

Debian / RPM

/var/lib/neo4j/certificates

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal and run cd certificates.

Configuration

The configuration directory contains the Neo4j configuration settings, Log4j configuration settings, and the JMX access credentials. For details about neo4j.conf, see The neo4j.conf file.

File permissions

Read only

Table 3. configuration directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/conf/neo4j.conf
<NEO4J_HOME>/conf/neo4j-admin.conf
<NEO4J_HOME>/conf/server-logs.xml
<NEO4J_HOME>/conf/user-log.xml

Windows

<NEO4J_HOME>\conf\neo4j.conf
<NEO4J_HOME>\conf\neo4j-admin.conf
<NEO4J_HOME>\conf\server-logs.xml
<NEO4J_HOME>\conf\user-log.xml

Debian / RPM

/etc/neo4j/neo4j.conf
/etc/neo4j/neo4j-admin.conf
/etc/neo4j/server-logs.xml
/etc/neo4j/user-log.xml

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal and run cd conf.

Data

The data directory contains all data-related content, such as databases, transactions, cluster-state (if applicable), dumps, and the cypher.script files (from the neo4j-admin database restore command). The data directory is internal to Neo4j and its structure is subject to change between versions without notice.

File permissions

Read and write.

Table 4. data directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/data

Windows

<NEO4J_HOME>\data

Debian / RPM

/var/lib/neo4j/data

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd data.

Import

The import directory contains all CSV files that the command LOAD CSV uses as sources to import data in Neo4j.

File permissions

Read only

Table 5. import directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/import

Windows

<NEO4J_HOME>\import

Debian / RPM

/var/lib/neo4j/import

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd import.

Labs

The labs directory contains APOC Core. For more information, see APOC User Guide → Installation.

File permissions

Read only.

Table 6. labs directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/labs

Windows

<NEO4J_HOME>\labs

Debian / RPM

/var/lib/neo4j/labs

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd labs.

Lib

The lib directory contains all Neo4j dependencies.

File permissions

Read only.

Table 7. lib directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/lib

Windows

<NEO4J_HOME>\lib

Debian / RPM

/usr/share/neo4j/lib

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd lib.

Licenses

The licenses directory contains Neo4j license files.

File permissions

Read only.

Table 8. licenses directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/licenses

Windows

<NEO4J_HOME>\licenses

Debian / RPM

/var/lib/neo4j/licenses

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd licences.

Logs

The logs directory contains the Neo4j log files.

File permissions

Read and write.

Table 9. logs directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/logs [1]

Windows

<NEO4J_HOME>\logs

Debian / RPM

/var/log/neo4j/ [2]

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd logs.

1. To view neo4j.log in Docker, use docker logs <containerID/name>.
2. To view the neo4j.log for Debian and RPM, use journalctl --unit=neo4j.

Metrics

The metrics directory contains the Neo4j built-in metrics for monitoring the Neo4j DBMS and each individual database.

File permissions

Read and write.

Table 10. metrics directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/metrics

Windows

<NEO4J_HOME>\metrics

Debian / RPM

/var/lib/neo4j/metrics

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd metrics.

Plugins

The plugins directory contains custom code that extends Neo4j, for example, user-defined procedures, functions, and security plugins.

File permissions

Read only.

Table 11. plugins directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/plugins

Windows

<NEO4J_HOME>\plugins

Debian / RPM

/var/lib/neo4j/plugins

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd plugins.

Products

The products directory contains the JAR files of the Neo4j products.

For Enterprise Edition, these are:

Community Edition contains:

  • GenAI plugin.

  • Fleet management. Starting with Neo4j 2026.03, Fleet Manager is built-in and enabled by default, therefore, the plugin is no longer supported.

Using the Fleet management plugin in Neo4j CE deployments is subject to some limitations due to the limited set of features, such as no metrics being available. Also, it is offered on a best-effort basis. Neo4j does not offer any technical support for it.

File permissions

Read only.

Table 12. products directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/products

Windows

<NEO4J_HOME>\products

Debian / RPM

/var/lib/neo4j/products

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd products.

Run

The run directory contains the processes IDs.

File permissions

Read and write.

Table 13. run directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/run

Windows

<NEO4J_HOME>\run

Debian / RPM

/var/lib/neo4j/run

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd run.

Web

Starting from Neo4j 2026.02.3, a new directory web is introduced in the Neo4j Community Edition. The web directory contains Neo4j Browser bundled as a .zip file.

The Neo4j Enterprise Edition does not include the web directory; and Neo4j Browser continues to be distributed as a .jar file located in the lib directory.

File permissions

Read only.

Table 14. web directory default location per distribution
Neo4j distribution Default file location

Linux / macOS / Docker

<NEO4J_HOME>/web

Windows

<NEO4J_HOME>\web

Debian / RPM

/var/lib/neo4j/web

Neo4j Desktop

From the Open dropdown menu of your active Neo4j DBMS, select Terminal, and run cd web.

Customize your file locations

The file locations can also be customized by using environment variables and options.

The locations of <NEO4J_HOME> and conf can be configured using environment variables:

Table 15. Configuration of <NEO4J_HOME> and conf
Location Default Environment variable Notes

<NEO4J_HOME>

parent of bin

NEO4J_HOME

Must be set explicitly if bin is not a subdirectory.

conf

<NEO4J_HOME>/conf

NEO4J_CONF

Must be set explicitly if it is not a subdirectory of <NEO4J_HOME>.

The rest of the locations can be configured by uncommenting the respective setting in the conf/neo4j.conf file and changing the default value.

#server.directories.data=data
#server.directories.plugins=plugins
#server.directories.logs=logs
#server.directories.lib=lib
#server.directories.run=run
#server.directories.licenses=licenses
#server.directories.metrics=metrics
#server.directories.transaction.logs.root=data/transactions
#server.directories.dumps.root=data/dumps
#server.directories.import=import

Security considerations

If a directory stores sensitive data, it must never be world-readable or world-executable. Even if files inside are restricted, a world-executable directory can leak structure.

  • On Linux, follow the recommendations:

    Scenario Recommended mode

    Only owner can access

    700

    Owner and specific group may have access

    750

    Ensure the process creating the directory uses a restrictive umask (e.g., 077) to prevent overly permissive defaults.

  • On Windows, allow access only to the owning account (or service account) and Administrators. Remove access for Users, Authenticated Users, and Everyone.
    Before removing broad permissions disable inheritance on the directory, otherwise they may be reintroduced from the parent directory.

Consider security recommendations above when creating a directory for backup files.

Glossary

allocator

A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.

asynchronous replication

Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.

Aura instance

A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.

auto-commit transaction

An automatically committed transaction that contains a single query.

Bolt protocol

Bolt is a protocol used for interaction between Neo4j instances and drivers.

bookmark

A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.

category (Bloom)

A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).

causal consistency

All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.

cluster

A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.

client application

Software that interacts with a Neo4j server.

commit

A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.

composite database

Composite databases are the means to access partitioned graph data with a single Cypher query.

constraint

Constraints are sets of data modeling rules that ensure the data is consistent and reliable.

Cypher®

Neo4j’s graph query language.

data model

A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.

database

A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.

database vs graph

Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.

Database Management System

Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.

database schema

The prescribed property existence and datatypes for nodes and relationships.

deallocate

An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.

degree (of a node)

The number of relationships of a specific node; loops are counted twice.

disaster recovery

A manual intervention to restore availability of a cluster, or databases within a cluster.

driver

A software library that provides access to Neo4j from a particular programming language.

election

In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.

entity

A node or a relationship.

expression (Cypher)

A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.

fabric

Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.

fault tolerance

A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.

follower

A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.

Generative AI (GenAI)

A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.

graph

A logical representation of a set of nodes where some pairs are connected by relationships.

index

Data structure that improves read performance of a database.

knowledge graph

A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.

label

Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.

leader

A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.

main database

In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.

motif

A description of a specific pattern within a graph.

node

A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.

operator

A symbol representing a mathematical or logical operation.

parameter

Named value provided when running a Cypher statement.

path

A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.

pattern

A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.

perspective (Bloom)

A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.

primary

A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.

primary vs secondary

In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.

project (Aura)

An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.

property

Properties are key-value pairs that are used for storing data on nodes and relationships.

query (Cypher)

A statement that retrieves or writes information to a database.

Raft group

A group of servers that are participating in hosting a particular database in primary mode.

Raft group member

A server that is participating in a Raft group. A server can be a member of one or more groups.

Raft log

A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.

Raft protocol

The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.

read scaling

Distributing query load by creating additional database copies hosted in secondary mode (read-only).

relationship

A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.

secondary

An asynchronously replicated copy of the database that provides read scaling within the cluster.

seed

A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.

server

A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.

session

A causally linked sequence of transactions.

session consistency

An alternative name for Neo4j’s causal consistency.

standalone

A single server running Neo4j and not part of a cluster.

synchronous replication

Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.

system database

A database used by Neo4j to store system information.

tenant (Aura)

An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.

tool asset database

In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.

topology

A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.

transaction

A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).