A single audit flag entry, combining an event class with its recording-mode prefix. The flags list in audit_control(5) is a comma-separated sequence of these entries.
Fields
| Field Name | Description |
|---|---|
class - AuditFlagClass!
|
The BSM audit event class being configured. |
prefix - AuditFlagPrefix!
|
The recording mode controlling which outcomes (success, failure, or both) are captured for this class. |
Used by
AuditPolicyMacOStype: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.
Example
Example
{"class": "AA", "prefix": "BOTH"}