---
title: AuditPolicyMacOS type | Wartiva GraphQL API
description: macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon.
url: https://wartiva.com/api-docs/types/audit-policy-mac-os.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `AuditPolicyMacOS` type

macOS-specific audit policy configuration, sourced from /etc/security/audit_control and the running audit daemon. Field names correspond directly to the parameter names defined in audit_control(5).

## Fields

| Field Name | Description |
|---|---|
| `directories` - [`[String!]!`](https://wartiva.com/api-docs/types/string.html) | Directories where audit trail files are stored. Corresponds to one or more dir: entries in audit_control(5). Changes require an audit daemon restart to take effect. |
| `dist` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | When true, auditd(8) creates hard links to all trail files in /var/audit/dist for consumption by auditdistd(8). Corresponds to the dist: parameter in audit_control(5). |
| `expireAfter` - [`AuditExpireAfter`](https://wartiva.com/api-docs/types/audit-expire-after.html) | Expiration policy controlling when old trail files are automatically removed. Corresponds to the expire-after: parameter in audit_control(5). Null when expiration is not configured. |
| `fileSize` - [`Int64!`](https://wartiva.com/api-docs/types/int64.html) | Maximum trail file size in bytes before auditd(8) rotates to a new file. Zero disables size-based rotation. Corresponds to the filesz: parameter in audit_control(5). |
| `flags` - [`[AuditFlag!]!`](https://wartiva.com/api-docs/types/audit-flag.html) | System-wide audit flag mask controlling which event classes are audited for all users. Per-user overrides are defined in audit_user(5). Corresponds to the flags: parameter in audit_control(5). |
| `host` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Hostname or IP address embedded in the header of each audit record. Corresponds to the host: parameter in audit_control(5). Empty when not configured. |
| `logFileSettings` - [`[AuditLogFileSettings!]!`](https://wartiva.com/api-docs/types/audit-log-file-settings.html) | Metadata for each audit trail file currently managed by the audit daemon. |
| `minFree` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | Minimum free disk space percentage on the audit log file system, on a 0 to 100 scale (not a 0 to 1 fraction), e.g. 20 meaning 20%. auditd(8) emits a warning when free space falls below this threshold. Corresponds to the minfree: parameter in audit_control(5). Defaults to 20 when not set. |
| `naFlags` - [`[AuditFlag!]!`](https://wartiva.com/api-docs/types/audit-flag.html) | Audit flags applied to events that cannot be attributed to a specific user (e.g., events occurring before login). Corresponds to the naflags: parameter in audit_control(5). |
| `policy` - [`[AuditControlPolicyFlag!]!`](https://wartiva.com/api-docs/types/audit-control-policy-flag.html) | Global behavioral policy flags for the audit subsystem. Corresponds to the policy: parameter in audit_control(5). |
| `queueSize` - [`Int!`](https://wartiva.com/api-docs/types/int.html) | Maximum number of committed audit records that may queue in the kernel pending write to disk. User threads are suspended when this limit is reached. Corresponds to the qsize: parameter in audit_control(5). Zero indicates the kernel default. |

## Used by

- [`AuditPolicy`](https://wartiva.com/api-docs/types/audit-policy.html) type: The security event auditing configuration of an Endpoint.
- [`AuditPolicyOsSpecific`](https://wartiva.com/api-docs/types/audit-policy-os-specific.html) union: OS-specific audit policy union type.

## Example

### Example

```json
{
  "directories": ["abc123"],
  "dist": true,
  "expireAfter": AuditExpireAfter,
  "fileSize": "-8589934592",
  "flags": [AuditFlag],
  "host": "xyz789",
  "logFileSettings": [AuditLogFileSettings],
  "minFree": 123,
  "naFlags": [AuditFlag],
  "policy": ["AHLT"],
  "queueSize": 987
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
