First, as role secadmin at label admin_low
, check to see if the kernel preselection mask matches the nonattributable events in the naflags: field of the audit_control(4) file by issuing the command:
$ auditconfig -getkmask |
If they differ, issue the command:
$ auditconfig -setkmaskac |