The past week I'm noticing over 40+ events of TermService in the event logs under System.
The description of the event is: Remote session from client name a exceeded the maximum allowed failed logon attempts. The session was forcibly terminated.
From my understanding of this is that it's someone or something attempting to log into our main server. There are times where this message appears every 5 seconds for 10-20 minutes non-stop. I don't want to cause alarm, within the company, but I'm starting to get worried. My boss is on vacation in Mexico and we have a Network Engineer that helps us out if needed.
Are these events really from someone trying to break into our server or something else?