I'm seeing no IP information in this security event. Source Workstation is "windows7" or "freerdp"
Keep in mind...the error code means "user does not exist" so in this case the user list is about 1800 user names like "scanner" "testuser" "support" to name a few. Has anyone seen this activity? the host value in the event is a DC...but this activity is typically a transition auth from the file server or member server which shows an 8004 event on that side. This activity has no pattern, so running packet capture hasn't helped as this behavior runs at any given time.