--- id: V-38541 status: implemented tag: auditd --- For Ubuntu, rules are added to auditd that will log any changes made in the ``/etc/apparmor`` directory. For CentOS, rules are added to auditd that will log any changes made in the ``/etc/selinux`` directory. To opt-out of this change, set the following Ansible variable: .. code-block:: yaml security_audit_mac_changes: no