Endpoint configuration · GraphQL type

AuditExpireAfter type

Expiration policy for audit trail files, corresponding to the expire-after parameter in audit_control(5). A file is removed when the applicable condition(s) are satisfied.

Fields

Field Name Description
age - Duration Maximum age of a trail file before it is eligible for removal, expressed in nanoseconds. Parsed from suffixed values in audit_control(5): s (seconds), h (hours), d (days), y (years). Null when no age condition is configured.
diskSize - Int64 Maximum aggregate size (in bytes) of all trail files before the oldest is eligible for removal. Parsed from suffixed values in audit_control(5): B, K (kibibytes), M (mebibytes), G (gibibytes). Null when no disk-space condition is configured.
operator - AuditExpireAfterOperator Logical operator combining the age and diskSize conditions. Null when only one condition is present.

Used by

  • AuditPolicyMacOS type: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.

Example

Example

{
  "age": "600000000",
  "diskSize": "-8589934592",
  "operator": "AND"
}