(Windows 2012 R2 server with SQL 2012.) Windows Application log is filled with the following informational event several times a minute.
Login failed for user <user name>. Reason: Password did not match that for the login provided. [CLIENT: <IP>]
The user name is a SQL login name and not a Windows account. I believe this account is used by all users within the SQL application but I am not sure. The IP address shows those for many different computers from different subnets. The event is reported all hours of the day except maybe between midnight and 4:30 am.
Short of checking all the PC's and a large number of scheduled tasks on the SQL server, is there a simple way to determine where these are coming from?