mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-18 11:53:37 +00:00
rephrase
This commit is contained in:
@ -68,7 +68,7 @@ Microsoft Defender for Endpoint utilized `audit` framework from linux to track n
|
||||
service auditd start
|
||||
```
|
||||
|
||||
**On SLES 12 and 15** systems, SYSCALL auditing in `auditd` is disabled by default and can explain missing events.
|
||||
**On SLES** systems, SYSCALL auditing in `auditd` might be disabled by default and can be accounted for missing events.
|
||||
|
||||
1. To validate that SYSCALL auditing is not disabeld, list the current audit rules:
|
||||
|
||||
|
Reference in New Issue
Block a user