Events logged on an Active Directory domain controller when a user supplies a bad password
I had to recently troubleshoot an account lockout issue for a client and as it’s been a while since I’ve had to troubleshoot such an issue, I completely forgot the type of logs that were