First, as role secadmin at label admin_low, check to see if the kernel preselection mask matches the class mappings in the flags: field of the audit_control(4) file by issuing the command:
| $ auditconfig -chkconf | 
If the runtime class mappings differ from the kernel cache, issue the command:
| $ auditconfig -conf |