Use WordPress brute force attack protecting plugins like https://wordpress.org/plugins/wp-limit-login-attempts/
i use admin username changer plugin along with limit login attempts plugin which locks out for 24hrs after 3 attempts and emails you when attempts happen, i also use a secret question and answer plugin like you get for banks. so if some is trying they have to get three things right to get in