First, as role secadmin at label admin_low
, check to see if the kernel preselection mask matches the class mappings in the flags: field of the audit_control(4) file by issuing the command:
$ auditconfig -chkconf |
If the runtime class mappings differ from the kernel cache, issue the command:
$ auditconfig -conf |