Where are the audit logs for failed/unauthorized password requests?

Where are the audit logs for failed/unauthorized password requests?

We are evaluating PMP right now.  When I try to access a password from an unauthorized user or from an unauthorized machine, I don't see anything in the audit logs about that.  Where is this information kept?  (or am I just missing it somewhere?)  I would assume that someone trying over and over again to get access to information they should not have would be logged somewhere.   Thanks for your help.
 
-John

                  New to ADSelfService Plus?