Various re-wordings and some minor additions:
- Don't say "by default" regarding paths in /etc/security: they are not configurable.
- Note that the 'ip' event class covers more than just System V IPC.
- Clarify the differences between the audit_control and audit_user files in the configuration files introduction.
- Slightly reword audit log rotiation introduction.
- Add a section on the 'audit' group, and how this can be used to delegate audit review rights.
Obtained from: TrustedBSD Project