Two solutions.
As per JPA's post (or edit the Group definition directly at open-audit/code_igniter/application/controllers/groups/RedHatSystems.xml)
I could also put a check in the processing of the audit script to force it to be os_family = "RedHat".
Typically (for example) Windows is:
os_group = Windows
os_family = Windows 2003
os_name = Windows 2003 Enterprise Server (whatever)
For Linux based systems we essentially have another level.
os_group = Linux
os_distribution = RedHatos_family = RedHat Server
os_name = RedHat Enterprise Server 5.4 (whatever)
We obviously don't have an os_distribution column and I don't really want to make one. We would be without a column to know the distribution, but we could always (as per JPA's group definition change) filter using a like% clause instead of an =.
RedHat is likely a bad (very simple) example - think of the different Ubuntu flavour for instance... still, os_family like "%ubuntu% should cater to that as well.
I think I'll propose sticking to the group definition change for now unless someone can convince me otherwise