Metadata about an active audit log file as reported by the running audit daemon.
Fields
| Field Name | Description |
|---|---|
fileName - String!
|
Absolute path to the audit trail file on disk. |
guid - Int!
|
File generation identifier assigned by the audit daemon, represented as an operating system user identifier (UID). |
mode - Uint32!
|
POSIX file permission mode bits of the trail file. |
uid - Int!
|
The operating system user identifier (UID) of the owner of the trail file. |
Used by
AuditPolicyMacOStype: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.
Example
Example
{
"fileName": "xyz789",
"guid": 987,
"mode": "1073741824",
"uid": 123
}