Hi Ali:
You have to create a query that matches the logic in the policy rule.
It looks like you are most interested in reporting on Exceptions. There are several Exceptions reports provided by IBM that you can clone and use for your purposes.
But I can try to explain, you want to create the query in the Exceptions Domain and the main difference between login failures and SQL errors is that you will want a condition of 'Exception Type = LOGIN_FAILED or SQL_ERROR' in order to get the events that you want to capture. Then add in the other conditions that you use in your policy, like IN GROUP. I attached a snapshot as example.
Thresholding is a little tougher, but you can exclude the timestamp and add a count. Then provide the from and to period when you execute the query. Or leverage an audit process or alert.
Thanks,
------------------------------
Wendy Zemba
------------------------------