The audit service is enabled by default. If the perzone audit policy is set, zone administrators must enable, refresh, or disable the audit service in each non-global zone as desired. If the perzone audit policy is not set, enabling, refreshing, or disabling the audit service from the global zone is effective for all non-global zones.
To disable or enable the audit service, you must become an administrator who is assigned the Audit Control rights profile. For more information, see Using Your Assigned Administrative Rights in Securing Users and Processes in Oracle Solaris 11.2 .
To disable the audit service, use the following command:
# audit -t
To enable the audit service, use the following command:
# audit -s
To verify that the audit service is running, use the following command:
# auditconfig -getcond audit condition = auditing
If the perzone audit policy is set, then you must perform this verification in the non-global zones where you enabled auditing.