(In reply to Johannes Segitz from comment #6) > Seems like Enzo already found the problem. How did you fix it Enzo? Seems to > me like this needs changes to the policy That's right. Here's the patch I'm testing: https://build.opensuse.org/package/view_file/home:ematsumiya:branches:security:SELinux/selinux-policy/fix_auditd.patch?expand=1 Works fine on TW, but I'll test on microOS to make sure I didn't miss anything else.