Denis
01/19/2024, 1:41 PMStefano Bonicatti
01/19/2024, 1:47 PMDenis
01/19/2024, 2:11 PMBrian Bergstrand
01/19/2024, 4:15 PMman 8 audit
. And ES currently does not provide socket events; a Network Extension would be required.Denis
01/19/2024, 6:30 PMsudo cp /etc/security/audit_control.example /etc/security/audit_control
and
sudo /bin/launchctl enable system/com.apple.auditd
and
sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.auditd.plist
ONLY after full reboot macos...Brian Bergstrand
01/19/2024, 6:31 PMDenis
01/19/2024, 6:32 PM