SQL Server Failed Login Alert


Use the Failed Login alert in Mini DBA to monitor SQL Server instances and make this condition visible before it becomes a wider database incident.

Screenshot pending: Mini DBA SQL Server Failed Login alert screenshot placeholder

Alert Summary

  • Platform: SQL Server
  • Alert category: General
  • Default enabled: true
  • Default evaluation frequency: Minute

What Mini DBA Checks

Mini DBA describes this alert as: A connection was attempted to the SQL Server but the login was incorrect The default evaluation frequency is Minute, so the alert is intended to be close enough to operational reality for live triage.

Why This Alert Is Helpful

This alert helps administrators notice security-sensitive events before they become routine background noise. Failed authentication, expiring passwords, or audit issues can indicate access problems, misconfiguration, or active probing.

When To Enable It

Enable it on production, shared, regulated, and externally reachable environments. You can use lower severity in isolated development systems, but keeping the signal visible helps catch account and permission drift early.

Threshold Guidance

This alert is not primarily driven by a numeric threshold in Mini DBA. Tune the schedule, scope, severity, and notification route so that the alert matches the importance of the instance. Use higher thresholds on batch-heavy, development, or intentionally bursty systems where brief pressure is expected. Use lower thresholds on latency-sensitive production systems, small instances with little headroom, and services with strict recovery or availability commitments.

Remediation For An Active Alert

Free space by removing safe-to-delete files, expanding the volume or tablespace, moving growth-heavy objects, correcting retention settings, or shrinking only after a documented one-off event. For recovery-related areas, verify that backups and log shipping or archiving are healthy before deleting anything.

Investigation Workflow

  1. Confirm the alert is still active and note the first seen time, affected instance, and severity.
  2. Review the affected disk, tablespace, log stream, backup job, retention setting, and recent growth pattern in Mini DBA before changing configuration or ending sessions.
  3. Compare the current value with the normal baseline for the same time of day or maintenance window.
  4. Record the cause, corrective action, and whether thresholds or routing should be adjusted after the incident.

Avoiding Alert Noise

Storage alerts should usually stay enabled even on quiet systems because the impact of missing them is high. Tune warning thresholds to leave enough time for approval, provisioning, and validation, especially when storage changes are handled by another infrastructure team.

Related Pages