Do you mean something like this?
kernel: [11610.173703] audit: type=1400 audit(1532519381.361:111): apparmor="DENIED" operation="ptrace" profile="/usr/lib/snapd/snap-confine" pid=4487 comm="snap-confine" requested_mask="read" denied_mask="read" peer="unconfined"
Do you mean something like this?
kernel: [11610.173703] audit: type=1400 audit(153251938 1.361:111) : apparmor="DENIED" operation="ptrace" profile= "/usr/lib/ snapd/snap- confine" pid=4487 comm="snap-confine" requested_ mask="read" denied_mask="read" peer="unconfined"