---
title: AuditFlagClass enum | Wartiva GraphQL API
description: Audit event class as defined in audit_class(5). Identifies the category of events being audited in the macOS BSM (Basic Security Module) audit subsystem.
url: https://wartiva.com/api-docs/types/audit-flag-class.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `AuditFlagClass` enum

Audit event class as defined in audit_class(5). Identifies the category of events being audited in the macOS BSM (Basic Security Module) audit subsystem. The class abbreviations correspond to entries in /etc/security/audit_class.

## Values

| Enum Value | Description |
|---|---|
| `AA` | Authentication and Authorization events — tracks successful and failed authentication attempts and authorization decisions. |
| `AD` | Administrative events — tracks administrative actions taken on the system. |
| `ALL` | All audit classes — a pseudo-class that matches every defined audit class. Use with care as it produces a very high volume of audit records. |
| `AP` | Application-defined events — tracks events generated by applications using the BSM audit API. |
| `CL` | File close events — tracks close(2) system calls on file descriptors. |
| `EX` | Program execution events — tracks execve(2) calls. When the argv or arge policy flags are set, command-line arguments and environment variables are also recorded. |
| `FA` | File and attribute access events — tracks stat(2) and similar calls that read file metadata without modifying the file. |
| `FC` | File create events — tracks creation of new files and directories. |
| `FD` | File delete events — tracks unlink(2), rmdir(2), and similar calls that remove file system objects. |
| `FM` | File attribute modify events — tracks chmod(2), chown(2), and similar calls that change file metadata. |
| `FR` | File read events — tracks read(2) and similar calls on file descriptors. |
| `FW` | File write events — tracks write(2) and similar calls on file descriptors. |
| `IO` | ioctl events — tracks ioctl(2) system calls. |
| `IP` | Interprocess communication events — tracks IPC operations such as shared memory, message queues, and semaphores. |
| `LO` | Login and logout events — tracks user login, logout, and session lifecycle events. This class is typically always enabled and corresponds to the lo flag in audit_control(5). |
| `NA` | Non-attributable events — tracks events that cannot be attributed to a specific user, such as actions taken before authentication completes. Corresponds to the naflags parameter in audit_control(5). |
| `NO` | Invalid audit class — when used as a prefix modifier in a flag set, disables auditing for the associated class. Not a real event class. |
| `NT` | Network events — tracks network-related system calls such as connect(2), bind(2), and accept(2). |
| `OT` | Other events — tracks miscellaneous events not covered by a more specific class. |
| `PC` | Process events — tracks process lifecycle operations such as fork(2), exit(2), and kill(2). |
| `SS` | System-wide security state change events — tracks audit configuration changes, audit log rotation, and other kernel-level security state transitions. |

## Used by

- [`AuditFlag`](https://wartiva.com/api-docs/types/audit-flag.html) type: A single audit flag entry, combining an event class with its recording-mode prefix.

## Example

### Example

```json
"AA"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
