You can identify attackers attempting to guess passwords by trying many combinations against one or more accounts.
In the search controls, set the Status filter to failed and click Search.
In the grid view, sort by the Src Addr column to group all failed attempts from a single IP address.
Analyze the results:
A high number of failed attempts from one source to a single target account indicates a brute-force attack.
A high number of failed attempts from one source to many different target accounts suggests a password-spraying attack.
Analyze the Cache Hits column. A high number indicates many identical, repeated logon attempts, which strengthens the evidence of an automated attack.