I have this applied to all my AD infrastructure servers, works great! But, I would like to stop this particular alert that is causing this to show up under 'Critical' and do not see how to shut this alert off?
'Account failed to logon event'
By default that it triggered by the number of events it gets for that ID. On the application page, hit "Edit the application monitor" find the Account failed to logon event component, and then alter the Statistic threshold by overriding the template. You can either remove the number to have it never go to warning or critical, or set new thresholds, either manually or using a baseline calculation. The baseline will still be met occasionally, but it will be less.