Verify group who owns the files under directory /var/audit
The group of the audit logs must be wheel.
[Root_Group]
The audit files are under /var/audit; set the group for each via chgrp.
oval:org.secpod.oval:def:24626
SCAP Repo OVAL Definition
2015-06-11