When you make changes to the /etc/security/audit_event or /etc/security/audit_class configuration files for the audit service, you must refresh the svc:/system/auditset:default service. Administrators who are assigned the Audit Configuration rights profile and the Service Configuration rights profile first configure auditing then refresh the service as follows:
$ pfbash ; auditconfig -conf $ svcadm refresh auditset:default