I would like to formulate something along the lines of correlating bad password attempts with locked accounts. Is that possible?
Look at this.
Locked account event tracing
https://answers.splunk.com/answers/300823/how-to-detect-domain-lockouts-and-configure-an-ale.html
failed login attempts
https://answers.splunk.com/answers/435873/how-to-search-for-failed-login-attempts.html
Locked account for which software? Maybe Active Directory Lockout alerts
In active directory lockout alerts, the search would only give me the locked accounts. Is there any way for the alert to show the failed login attempts made before the account gets locked out?