O endereço IP para tentativas de RDP com falha é registrado aqui, mesmo com o NLA habilitado (nenhum ajuste é necessário) (testado no Server 2012 R2, não tenho certeza sobre outras versões)
Logs de aplicativos e serviços > Microsoft-Windows-RemoteDesktopServices-RdpCoreTS / operacional (ID do evento 140)
Exemplo de texto registrado:
A connection from the client computer with an IP address of 108.166.xxx.xxx failed because the user name or password is not correct.
XML:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-RemoteDesktopServices-RdpCoreTS" Guid="{1139C61B-B549-4251-8ED3-27250A1EDEC8}" />
<EventID>140</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>4</Task>
<Opcode>14</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2016-11-13T11:52:25.314996400Z" />
<EventRecordID>1683867</EventRecordID>
<Correlation ActivityID="{F4204608-FB58-4924-A3D9-B8A1B0870000}" />
<Execution ProcessID="2920" ThreadID="4104" />
<Channel>Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational</Channel>
<Computer>SERVER</Computer>
<Security UserID="S-1-5-20" />
</System>
- <EventData>
<Data Name="IPString">108.166.xxx.xxx</Data>
</EventData>
</Event>