In the action log, in case of authentication failure, the username that was used is not saved.
Therefore, there is no way to know who failed to connect and potentially, which account are being attacked.