Log on as an administrator via RDP
Click Start, click Run, type mmc /a (note the space between mmc and /a), and
then click OK.
On the File menu, click Add/Remove Snap-in, and then click Add.
Under Snap-in, click Group Policy, and then click Add.
In Select Group Policy Object, click Local Computer, click Finish, click
Close, and then click OK.
At this point, you might want to save this console for further use. Note you
can add multiple snap-in and manage multiple computers from this console.
On the left hand side, navigate to Local Computer Policy > Computer
Configuration > Windows Settings > Security Settings > Local Policies >
On the right hand side, double-click “Audit Logon Events”
Check the boxes for Success and Failure, click OK
The failed login attempts will be found in the Event Viewer. It will
include the time it happened, the username they used, and the IP they tried