I have a request to Monitor Windows Active directory accounts for the event ID 644 (User account lockout) with the event text containing specific account details. With a bit of time and effort I can probably write the script to scan the event logs for this event. Is there a better way using APM, or does anybody have a script that already does something similar?