Verify group who owns the files under directory /var/audit The group of the audit logs must be wheel. [Root_Group] The audit files are under /var/audit; set the group for each via chgrp. oval:org.secpod.oval:def:24626 SCAP Repo OVAL Definition 2015-06-11