Through the SQL Server Management Studio, enable auditing for SQL Server. At a minimum, enable failed login attempts. Auditing of failed login attempts only is enabled by default. ref. http://www.cisecurity.org/tools2/sqlserver/CIS_SQL2005_Benchmark_v1.0.pdf, pg 99.