Not my project. I was also going to post yours but decided not to due to questions in issues about support for newer versions of windows. Something about IP address missing from event?
Windows Server 2012 R2 removed the IP address from the Event Log entry for failed RDP logons (to be fair, it's really that the just didn't include it in failed RDP logons when the TLS security layer is used-- reverting to the old RDP security layer in Windows Server 2012 R2 restores the IP address). Without doing something dodgy like trying to correlate closed TCP connections to Event Log entries there's no simple way to ascribe IP addresses to failed RDP logons on that version of Windows.
In Windows Server 2016 and 2019 Microsoft put the IP address back into the Event Log entry, restoring ts_block's functionality.