First, relax: this isn't a targeted attack on you, it's background noise every public-facing address gets. Automated scanners constantly sweep IP ranges and try known vulnerability paths. They don't know what your site is, nor do they care.
Now for the skeptical part, because "normal" doesn't mean "unimportant." Make this distinction:
Automated noise: requests returning 404s on random paths, from different IPs, repeating patterns. This is just noise.
What to watch for: attempts on paths that actually exist on your site. Repeated password tries on your login page, access attempts to your admin panel, parameter tampering. This means someone has actually looked at your site.
To-do list, in order of importance: don't leave the admin panel public, rate-limit login attempts, keep software updated, have backups, and test them by restoring.
The last item is the most skipped. An untested backup is not a backup.