I'm trying to track random account lockouts on the domain. Is there any recommendations for log level or log handling that let me see what machines/servers are locking the account?

I'm using samba 4.5.5. as a DC (3 DCs).

My current logging settings are:

logging = syslog
log level = 1 auth:5 passdb:5 winbind:5


