We having random accounts lockout and a few account persistently among the lockouts. Using Netwrix account lockout examiner, it indicates the PDC from where the account is locked and the workstation as our exchange front end (2010). The details for event id 4625 on the exchange server does not have any information as to where the lockout is coming from so Source Network Address is blank. Anyone encountered this before? Attached are some of the details.