Endpoint configuration · GraphQL enum

AuditFlagPrefix enum

Recording mode prefix applied to an audit flag class. Controls whether successful events, failed events, both, or neither are recorded. Corresponds to the prefix characters defined in audit_control(5):

  • (none) → BOTH
    •   → SUCCESS_ONLY
      
    •   → FAILURE_ONLY
      
  • ^ → NEITHER
  • ^+ → NOT_SUCCESS
  • ^- → NOT_FAILURE

Values

Enum Value Description

BOTH

Record both successful and failed events. Corresponds to no prefix in audit_control(5).

FAILURE_ONLY

Record only failed events. Corresponds to the - prefix in audit_control(5).

NEITHER

Record neither successful nor failed events. Corresponds to the ^ prefix in audit_control(5). Effectively disables auditing for this class.

NOT_FAILURE

Do not record failed events (suppress failures only). Corresponds to the ^- prefix in audit_control(5).

NOT_SUCCESS

Do not record successful events (suppress successes only). Corresponds to the ^+ prefix in audit_control(5).

SUCCESS_ONLY

Record only successful events. Corresponds to the + prefix in audit_control(5).

Used by

  • AuditFlag type: A single audit flag entry, combining an event class with its recording-mode prefix.

Example

Example

"BOTH"