--- - name: Install audit ansible.builtin.apt: name: auditd state: latest notify: - Start auditd - Enable auditd when: ansible_facts['os_family'] == "Debian" - name: Install audit ansible.builtin.dnf: name: audit state: latest notify: - Start auditd - Enable auditd when: ansible_facts['os_family'] == "RedHat" - name: Add rules ansible.builtin.copy: src: custom.rules dest: /etc/audit/rules.d/custom.rules mode: "0640"