> auditctl -a user,never -F loginuid!=$LOGINUID
> auditctl -a user,always -F loginuid=$LOGINUID
>
With audit 0.9.11 and kernel.audit.64 on a pSeries system, it just prints
out the usage info (no other info about what it doesn't like) if I try
running any of the following commands:
auditctl -a user,never -F loginuid=500
auditctl -a user,never -F auid=500
auditctl -a user,always -F loginuid=500
auditctl -a user,always -F auid=500