Use the Failed Login Attempts alert in Mini DBA to monitor Oracle instances and make this condition visible before it becomes a wider database incident.
Mini DBA describes this alert as: Excessive failed login attempts detected May indicate brute force attack or misconfigured application Review security logs and consider account lockout policies The default evaluation frequency is Minute, so the alert is intended to be close enough to operational reality for live triage. Because duration is used, Mini DBA can avoid treating a single short spike as a full incident when the condition clears quickly.
This alert protects storage and recovery capacity. It helps you find growth, retention, and backup conditions that can stop writes, break recovery objectives, or leave the server without enough working space for normal database activity.
Enable it on production, shared, regulated, and externally reachable environments. You can use lower severity in isolated development systems, but keeping the signal visible helps catch account and permission drift early.
Threshold meaning: Failed attempts. Major threshold: 10 attempts. Minor threshold: 5 attempts. Comparison direction: "over". Duration is used, so prefer requiring the condition to persist before paging people for transient spikes. Use higher thresholds on batch-heavy, development, or intentionally bursty systems where brief pressure is expected. Use lower thresholds on latency-sensitive production systems, small instances with little headroom, and services with strict recovery or availability commitments.
Free space by removing safe-to-delete files, expanding the volume or tablespace, moving growth-heavy objects, correcting retention settings, or shrinking only after a documented one-off event. For recovery-related areas, verify that backups and log shipping or archiving are healthy before deleting anything.
Storage alerts should usually stay enabled even on quiet systems because the impact of missing them is high. Tune warning thresholds to leave enough time for approval, provisioning, and validation, especially when storage changes are handled by another infrastructure team.