You can do this at the following location:
Monitoring and Reports > Alarms > Thresholds > Add
- Select Critieria tab
- Set category as "Failed Authentications"
- Set failure reason as 13017
In this tab you can also set the threshold you want the alarm to be created for
In the notification tab define whether to send email and who too and/or create syslog event