audit_receive_filter — apply all rules to the specified message type
int audit_receive_filter
(int type, int pid, int uid, int seq, void * data, size_t datasz, uid_t loginuid, u32 sessionid, u32 sid);
audit message type
target pid for netlink audit messages
target uid for netlink audit messages
netlink audit message sequence (serial) number
payload data
size of payload data
loginuid of sender
sessionid for netlink audit message
SE Linux Security ID of sender