Endpoint configuration · GraphQL type

AuditPolicyMacOS type

macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon. Field names correspond directly to the parameter names defined in audit_control(5).

Fields

Field Name Description
directories - [String!]! Directories where audit trail files are stored. Corresponds to one or more dir: entries in audit_control(5). Changes require an audit daemon restart to take effect.
dist - Boolean! When true, auditd(8) creates hard links to all trail files in /var/audit/dist for consumption by auditdistd(8). Corresponds to the dist: parameter in audit_control(5).
expireAfter - AuditExpireAfter Expiration policy controlling when old trail files are automatically removed. Corresponds to the expire-after: parameter in audit_control(5). Null when expiration is not configured.
fileSize - Int64! Maximum trail file size in bytes before auditd(8) rotates to a new file. Zero disables size-based rotation. Corresponds to the filesz: parameter in audit_control(5).
flags - [AuditFlag!]! System-wide audit flag mask controlling which event classes are audited for all users. Per-user overrides are defined in audit_user(5). Corresponds to the flags: parameter in audit_control(5).
host - String! Hostname or IP address embedded in the header of each audit record. Corresponds to the host: parameter in audit_control(5). Empty when not configured.
logFileSettings - [AuditLogFileSettings!]! Metadata for each audit trail file currently managed by the audit daemon.
minFree - Int! Minimum free disk space percentage on the audit log file system, on a 0 to 100 scale (not a 0 to 1 fraction), e.g. 20 meaning 20%. auditd(8) emits a warning when free space falls below this threshold. Corresponds to the minfree: parameter in audit_control(5). Defaults to 20 when not set.
naFlags - [AuditFlag!]! Audit flags applied to events that cannot be attributed to a specific user (e.g., events occurring before login). Corresponds to the naflags: parameter in audit_control(5).
policy - [AuditControlPolicyFlag!]! Global behavioral policy flags for the audit subsystem. Corresponds to the policy: parameter in audit_control(5).
queueSize - Int! Maximum number of committed audit records that may queue in the kernel pending write to disk. User threads are suspended when this limit is reached. Corresponds to the qsize: parameter in audit_control(5). Zero indicates the kernel default.

Used by

Example

Example

{
  "directories": ["abc123"],
  "dist": true,
  "expireAfter": AuditExpireAfter,
  "fileSize": "-8589934592",
  "flags": [AuditFlag],
  "host": "xyz789",
  "logFileSettings": [AuditLogFileSettings],
  "minFree": 123,
  "naFlags": [AuditFlag],
  "policy": ["AHLT"],
  "queueSize": 987
}