A couple of weeks ago, it seems like we had a hacking attempt. We changed all passwords and set a group policy for locking user accounts after x attempts.
Unfortunately we had an admin account keep getting locked which killed services that used that account. I have changed the services to new accounts and the admin account, every so often gets locked.
Is there a report to find what workstation/server is doing the failed login attempts and locking the account?
Thanks
Joe