--- - name: Install audit ansible.builtin.apt: name: auditd state: latest notify: - Start auditd - Enable auditd when: ansible_facts['os_family'] == "Debian" - name: Install audit ansible.builtin.dnf: name: audit state: latest notify: - Start auditd - Enable auditd when: ansible_facts['os_family'] == "RedHat" - name: Add rules ansible.builtin.copy: src: 'custom.rules' dest: '/etc/audit/rules.d/custom.rules' mode: "0640"