Global audit policy flag as defined in the policy parameter of audit_control(5). Each flag controls a behavioral aspect of the macOS BSM audit subsystem.
Values
| Enum Value | Description |
|---|---|
|
|
Fail-stop: halt the system if auditing cannot continue due to a full audit store. The kernel drains pending records to disk before halting. Mutually exclusive with CNT in practice. Not recommended for most deployments. |
|
|
Audit environmental variable arguments passed to execve(2). Requires the EX audit class to be active. Produces verbose records; enable only when deep execution tracing is needed. |
|
|
Audit command-line arguments passed to execve(2). Requires the EX audit class to be active. |
|
|
Continue: allow processes to keep running even when the audit store is exhausted and events cannot be written. Recommended for most deployments to avoid denial-of-service from a full audit log partition. |
|
|
Include the supplementary groups list in generated audit records. Not implemented on Darwin; supplementary groups are never included on this platform. |
|
|
Include secondary file paths in audit records. Not implemented on Darwin; secondary paths are never included on this platform. |
|
|
Enable per-zone auditing. Not implemented on Darwin. |
|
|
Include a unique sequence number token in each audit record. Not implemented on Darwin. |
|
|
Append a trailer token to each audit record. Not implemented on Darwin; trailers are always included. |
|
|
Include a zone ID token with each audit record. Not implemented on Darwin. |
Used by
AuditPolicyMacOStype: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.
Example
Example
"AHLT"