If you start auditing without using a configuration file, the following defaults are used:
Shared memory is used as the IPC mechanism.
The Secure file emitter only is enabled, with the following characteristics:
Audit file collection size of 5.
20 Mb maximum size of each audit file in the collection.
Location in which the audit files are created: The value set in the environment variable:
MFAUDIT_LOGS
In the Windows environment, if the
MFAUDIT_LOGS environment variable is not set, the audit logs are created in the location set by the following registry key: