I am at a total loss here and sure would appreciate any help that the community could offer. I have a unique situation and am not sure how to address it. I need to build an alert based on the total number of locked out user accounts in our environment at any given time. I have an Iframe (widget) that displays the total count using a basic SQL query but I can't find a way to get that query into an alert so that it will work. It seems that being forced to select the tables in advance from the dropdown are what are causing me issues. Here is the query that works.
SELECT COUNT(*) FROM [dbo].[APM_WindowsEvent_Detail]
WHERE EventCode = 4740
AND [TimeGeneratedUtc] > DATEADD(hour,-1,GETUTCDATE())
This displays the total number of event logs that match the ID 4740 which gives me a good idea of the total number of locked accounts. Is there any way to get this query into an alert so that I can set some logic to alert anytime I see more than 50 locked accounts within a 30 minute period? Is there possibly another way to do this? I do have the Windows AD templates in place on all domain controllers counting the various account status details. Included is locked out accounts but it seems to be based on the event logs for the specific server that the template is assigned to (as you would expect it to be). I need to get a total count of all locked out accounts and generate an alert / email off that stat rather than what each server sees individually.
This is a real hot issue in our NOC currently so any help or suggestions would be most welcomed.