Audits module are used to collect information from host endpoints. Audits module is installed as system module with HX 10.0.0 or later. You can request an audit for host endpoints using data acquisition scripts and using the Endpoint Security (HX) API.
This feature allows you to enable or disable data acquisitions from the Agent Default policy. It allows you to create your own custom acquisition scripts and supports multifile acquisitions.
The output collected by an audits module can be reviewed using the Triage Viewer, the Audit Viewer, or in Enterprise Search. It can also be reviewed in the output produced by an API data acquisition request.
This module is supported on Windows, macOS and Linux platform. To know more about the Audits module, see Audit Reference Guide.