This file is indexed.

/etc/audit/audit-stop.rules is in auditd 1:2.8.2-1ubuntu1.

This file is owned by root:root, with mode 0o640.

The actual contents of the file can be viewed below.

1
2
3
4
5
6
7
8
# These rules are loaded when the audit daemon stops
# if configured to do so.

# Disable auditing
-e 0

# Delete all rules
-D