Expiration policy for audit trail files, corresponding to the expire-after parameter in audit_control(5). A file is removed when the applicable condition(s) are satisfied.
Fields
| Field Name | Description |
|---|---|
age - Duration
|
Maximum age of a trail file before it is eligible for removal, expressed in nanoseconds. Parsed from suffixed values in audit_control(5): s (seconds), h (hours), d (days), y (years). Null when no age condition is configured. |
diskSize - Int64
|
Maximum aggregate size (in bytes) of all trail files before the oldest is eligible for removal. Parsed from suffixed values in audit_control(5): B, K (kibibytes), M (mebibytes), G (gibibytes). Null when no disk-space condition is configured. |
operator - AuditExpireAfterOperator
|
Logical operator combining the age and diskSize conditions. Null when only one condition is present. |
Used by
AuditPolicyMacOStype: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.
Example
Example
{
"age": "600000000",
"diskSize": "-8589934592",
"operator": "AND"
}