Recording mode prefix applied to an audit flag class. Controls whether successful events, failed events, both, or neither are recorded. Corresponds to the prefix characters defined in audit_control(5):
- (none) → BOTH
-
→ SUCCESS_ONLY
-
→ FAILURE_ONLY
- ^ → NEITHER
- ^+ → NOT_SUCCESS
- ^- → NOT_FAILURE
Values
| Enum Value | Description |
|---|---|
|
|
Record both successful and failed events. Corresponds to no prefix in audit_control(5). |
|
|
Record only failed events. Corresponds to the - prefix in audit_control(5). |
|
|
Record neither successful nor failed events. Corresponds to the ^ prefix in audit_control(5). Effectively disables auditing for this class. |
|
|
Do not record failed events (suppress failures only). Corresponds to the ^- prefix in audit_control(5). |
|
|
Do not record successful events (suppress successes only). Corresponds to the ^+ prefix in audit_control(5). |
|
|
Record only successful events. Corresponds to the + prefix in audit_control(5). |
Used by
AuditFlagtype: A single audit flag entry, combining an event class with its recording-mode prefix.
Example
Example
"BOTH"