What data source is needed in order to detect brute force attacks against the Azure Portal?

I answered sign in logs but it seems it requires a longer answer. Does anyone know which one it is?

Azure AD Logs data source is needed in order to detect brute force attacks against the Azure Portal?](What data source is needed in order to detect brute force attacks against the Azure Portal?)