Syslog output appears to exist for this event; however, I haven't tried this myself.
Alarm Name: EvtSubAccLockedMaxHack
Severity: INFORMATIONAL_ALARM
Description: A user account has been locked as max number of invalid login attempts exceeded. Details - %1.
Route To: Event Log
Explanation: A user account has been locked as max number of invalid login attempts exceeded.
Recommended Action: None
The server has a syslog agent which collects any syslog alarm output from all of the individual daemons and allows for a unified output stream to a server of your choice. This is configured under Enterprise Parameters. If this generates too much information you can configure a trap for the individual alarm event under Serviciability. Cisco recommends the syslog agent due to the high quantity of alarm possibilities.
Alarm Definitions:
http://www.cisco.com/en/US/docs/voice_ip_comm/connection/8x/alarm_messages/85cucalrmmsgdef.html
Please remember to rate helpful responses and identify helpful or correct answers.