Endpoint configuration · GraphQL enum

AuditFlagClass enum

Audit event class as defined in audit_class(5). Identifies the category of events being audited in the macOS BSM (Basic Security Module) audit subsystem. The class abbreviations correspond to entries in /etc/security/audit_class.

Values

Enum Value Description

AA

Authentication and Authorization events — tracks successful and failed authentication attempts and authorization decisions.

AD

Administrative events — tracks administrative actions taken on the system.

ALL

All audit classes — a pseudo-class that matches every defined audit class. Use with care as it produces a very high volume of audit records.

AP

Application-defined events — tracks events generated by applications using the BSM audit API.

CL

File close events — tracks close(2) system calls on file descriptors.

EX

Program execution events — tracks execve(2) calls. When the argv or arge policy flags are set, command-line arguments and environment variables are also recorded.

FA

File and attribute access events — tracks stat(2) and similar calls that read file metadata without modifying the file.

FC

File create events — tracks creation of new files and directories.

FD

File delete events — tracks unlink(2), rmdir(2), and similar calls that remove file system objects.

FM

File attribute modify events — tracks chmod(2), chown(2), and similar calls that change file metadata.

FR

File read events — tracks read(2) and similar calls on file descriptors.

FW

File write events — tracks write(2) and similar calls on file descriptors.

IO

ioctl events — tracks ioctl(2) system calls.

IP

Interprocess communication events — tracks IPC operations such as shared memory, message queues, and semaphores.

LO

Login and logout events — tracks user login, logout, and session lifecycle events. This class is typically always enabled and corresponds to the lo flag in audit_control(5).

NA

Non-attributable events — tracks events that cannot be attributed to a specific user, such as actions taken before authentication completes. Corresponds to the naflags parameter in audit_control(5).

NO

Invalid audit class — when used as a prefix modifier in a flag set, disables auditing for the associated class. Not a real event class.

NT

Network events — tracks network-related system calls such as connect(2), bind(2), and accept(2).

OT

Other events — tracks miscellaneous events not covered by a more specific class.

PC

Process events — tracks process lifecycle operations such as fork(2), exit(2), and kill(2).

SS

System-wide security state change events — tracks audit configuration changes, audit log rotation, and other kernel-level security state transitions.

Used by

  • AuditFlag type: A single audit flag entry, combining an event class with its recording-mode prefix.

Example

Example

"AA"