Karl - I have the same issue with message audit logs. If can search on @example.com and get 200 records and then search on
Bob@example.com and get 210 rows (for a non-current time period, so it's not "new" mail).
We use SNMP for historical and more complete alerting - we are tracking queues - in / out / delivery - deferred & queued, memory usage, disk: boot, data, opt, swap, 5/10/15 min load average, interface traffic in/out KBs for each i/f, CPU - User/Sys (we are using the raw counters, as the managed counters are "sticky" - there is an open defect on this).
I'm interested in what useful MIBs you have found.