diff --git a/templates/audit/98_auditd_exception.rules.j2 b/templates/audit/98_auditd_exception.rules.j2 index 4bc8909..a453f3b 100644 --- a/templates/audit/98_auditd_exception.rules.j2 +++ b/templates/audit/98_auditd_exception.rules.j2 @@ -3,6 +3,6 @@ # This file contains users whose actions are not logged by auditd {% if allow_auditd_uid_user_exclusions %} {% for user in rhel9cis_auditd_uid_exclude %} --F uid!={{ user }} +-a never,user -F uid!={{ user }} -F auid!={{ user }} {% endfor %} {% endif %} \ No newline at end of file