Turns auditing on system-wide; auditctl -e 0 disables it and auditctl -e 2 locks the configuration until reboot. Rules added with auditctl apply immediately but are not persistent, so add them to /etc/audit/rules.d/ for boot-time loading. Confirm with auditctl -l.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.