The Ansible tasks will ensure that files in /var/log/audit are owned by the root user.
/var/log/audit