This will help to track down failed logins. This could be due to someone changing their password and still are logged in to a server with the old account information. The other side is that someone could be trying to brute force an account.
Type=”Failure Audit” sourcetype=”WinEventLog:Security” | chart count by User_Name | sort – count