Endpoint configuration · GraphQL enum

AuditControlPolicyFlag enum

Global audit policy flag as defined in the policy parameter of audit_control(5). Each flag controls a behavioral aspect of the macOS BSM audit subsystem.

Values

Enum Value Description

AHLT

Fail-stop: halt the system if auditing cannot continue due to a full audit store. The kernel drains pending records to disk before halting. Mutually exclusive with CNT in practice. Not recommended for most deployments.

ARGE

Audit environmental variable arguments passed to execve(2). Requires the EX audit class to be active. Produces verbose records; enable only when deep execution tracing is needed.

ARGV

Audit command-line arguments passed to execve(2). Requires the EX audit class to be active.

CNT

Continue: allow processes to keep running even when the audit store is exhausted and events cannot be written. Recommended for most deployments to avoid denial-of-service from a full audit log partition.

GROUP

Include the supplementary groups list in generated audit records. Not implemented on Darwin; supplementary groups are never included on this platform.

PATH

Include secondary file paths in audit records. Not implemented on Darwin; secondary paths are never included on this platform.

PERZONE

Enable per-zone auditing. Not implemented on Darwin.

SEQ

Include a unique sequence number token in each audit record. Not implemented on Darwin.

TRAIL

Append a trailer token to each audit record. Not implemented on Darwin; trailers are always included.

ZONENAME

Include a zone ID token with each audit record. Not implemented on Darwin.

Used by

  • AuditPolicyMacOS type: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.

Example

Example

"AHLT"