---
title: AuditFlag type | Wartiva GraphQL API
description: A single audit flag entry, combining an event class with its recording-mode prefix. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/audit-flag.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `AuditFlag` type

A single audit flag entry, combining an event class with its recording-mode prefix. The flags list in audit_control(5) is a comma-separated sequence of these entries.

## Fields

| Field Name | Description |
|---|---|
| `class` - [`AuditFlagClass!`](https://wartiva.com/api-docs/types/audit-flag-class.html) | The BSM audit event class being configured. |
| `prefix` - [`AuditFlagPrefix!`](https://wartiva.com/api-docs/types/audit-flag-prefix.html) | The recording mode controlling which outcomes (success, failure, or both) are captured for this class. |

## Used by

- [`AuditPolicyMacOS`](https://wartiva.com/api-docs/types/audit-policy-mac-os.html) type: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.

## Example

### Example

```json
{"class": "AA", "prefix": "BOTH"}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
