The audit daemon is enabled by default on Red Hat Enterprise Linux (RHEL). Use this procedure to verify the service status and list active rules for security tracking.
Prerequisites
You must have root privileges or sudo access.
The system must run RHEL version 7, 8, or 9.
Verify the audit daemon status
Check the status of the audit service.
sudo systemctl status auditd
List the active audit rules to confirm the kernel configuration.