Reports whether auditd is running and shows recent log lines, since the daemon consumes audit records and writes them to /var/log/audit/audit.log. If it is inactive, auditctl rules collect nothing. Start it with systemctl start auditd, and make sure the kernel audit subsystem is enabled.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.