macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon. Field names correspond directly to the parameter names defined in audit_control(5).
Fields
| Field Name | Description |
|---|---|
directories - [String!]!
|
Directories where audit trail files are stored. Corresponds to one or more dir: entries in audit_control(5). Changes require an audit daemon restart to take effect. |
dist - Boolean!
|
When true, auditd(8) creates hard links to all trail files in /var/audit/dist for consumption by auditdistd(8). Corresponds to the dist: parameter in audit_control(5). |
expireAfter - AuditExpireAfter
|
Expiration policy controlling when old trail files are automatically removed. Corresponds to the expire-after: parameter in audit_control(5). Null when expiration is not configured. |
fileSize - Int64!
|
Maximum trail file size in bytes before auditd(8) rotates to a new file. Zero disables size-based rotation. Corresponds to the filesz: parameter in audit_control(5). |
flags - [AuditFlag!]!
|
System-wide audit flag mask controlling which event classes are audited for all users. Per-user overrides are defined in audit_user(5). Corresponds to the flags: parameter in audit_control(5). |
host - String!
|
Hostname or IP address embedded in the header of each audit record. Corresponds to the host: parameter in audit_control(5). Empty when not configured. |
logFileSettings - [AuditLogFileSettings!]!
|
Metadata for each audit trail file currently managed by the audit daemon. |
minFree - Int!
|
Minimum free disk space percentage on the audit log file system, on a 0 to 100 scale (not a 0 to 1 fraction), e.g. 20 meaning 20%. auditd(8) emits a warning when free space falls below this threshold. Corresponds to the minfree: parameter in audit_control(5). Defaults to 20 when not set. |
naFlags - [AuditFlag!]!
|
Audit flags applied to events that cannot be attributed to a specific user (e.g., events occurring before login). Corresponds to the naflags: parameter in audit_control(5). |
policy - [AuditControlPolicyFlag!]!
|
Global behavioral policy flags for the audit subsystem. Corresponds to the policy: parameter in audit_control(5). |
queueSize - Int!
|
Maximum number of committed audit records that may queue in the kernel pending write to disk. User threads are suspended when this limit is reached. Corresponds to the qsize: parameter in audit_control(5). Zero indicates the kernel default. |
Used by
AuditPolicytype: The security event auditing configuration of an Endpoint.AuditPolicyOsSpecificunion: OS-specific audit policy union type.
Example
Example
{
"directories": ["abc123"],
"dist": true,
"expireAfter": AuditExpireAfter,
"fileSize": "-8589934592",
"flags": [AuditFlag],
"host": "xyz789",
"logFileSettings": [AuditLogFileSettings],
"minFree": 123,
"naFlags": [AuditFlag],
"policy": ["AHLT"],
"queueSize": 987
}