Validating TACACS authentication via DW

We had a network wide issue today where all network devices were unable to authenticate via TACACS. Without going into to much detail, this ended up being a Cisco ISE bug. I'm curious if it's possible to monitor TACACS+ authentication attempts via SW and alert when TACACS attempts are not successful. I am wondering if I can leverage the fact that our instance of SW has a TACACS/AD account it uses to log into our Cisco Devices.