can I trace the ip of a failed administrator login

can I trace the ip of a failed administrator login

We are testing the audit manager and set an email alert to trigger when the administrator logs on to any machine and the password fails.

The alert does work but can we get more information like the IP address of where the log in is coming from if not from the local machine but say from an RDP or other type of connection.?

We are getting this alert trigger to a new domain server we are setting up and we are currently not logging in,

:)

                New to ADManager Plus?

                  New to ADSelfService Plus?