If you have more than an account that usually lockout to better investigate this kind of problem you can have this information from the Security Log
of your Domain Controller. If you have more than 1 DC, you can check
each of your DC for Event ID 4740 (it's an information). In this Event
Log, you will have the computer name of the logon request.
If you have a lot of DC, there is tool (Account Lockout and Management Tools) you can use --> http://www.microsoft.com/en-ca/download/details.aspx?id=18465
Then, locally on the computer, look for aomething that could run under under user account
* Service
* Scheduled task