> > auditctl -a user,never -F loginuid!=$LOGINUID
> > auditctl -a user,always -F loginuid=$LOGINUID
> >
With audit 0.9.11 and kernel.audit.64 on a pSeries system, it just prints out the usage info (no other info about what it doesn't like) if I try running any of the following commands:

auditctl -a user,never -F loginuid=500
auditctl -a user,never -F auid=500
auditctl -a user,always -F loginuid=500
auditctl -a user,always -F auid=500