---
title: "Best practices: System monitoring with SNMP/SMS/email targets"
slug: "oas-ag-best-practices-system-monitoring-3-28"
updated: 2025-07-04T10:04:19Z
published: 2025-07-07T13:24:13Z
canonical: "docs.onespan.com/oas-ag-best-practices-system-monitoring-3-28"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onespan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Best practices: System monitoring with SNMP/SMS/email targets

If you are using OneSpan Authentication Server system monitoring, we recommend to define targets for the following OneSpan Authentication Server events:

- OneSpan Authentication Server errors. For these type of events, you should define an audit filter that extracts all error audit messages.
- Locked authenticator users. For these type of events, you should define a filter that extracts all audit messages with the audit code 'W-011003'.
- Failed administrative logons. For these type of events, you should define a filter that extracts all audit messages with the audit code 'F-004001'.
- Replication failures. For these type of events, you should define a filter that extracts all audit messages with the audit codes 'F-003001' or 'F-003002'.
