Detect SSH Exploitation / Scanning Behaviour

This rule detects potential SSH brute force attacks by monitoring syslog for multiple failed SSH login attempts, connection closures, or invalid user attempts from a single source IP address within a short time frame. It specifically looks for keywords like 'error', 'Connection closed', 'authentication failure', and 'invalid user' in SSHD logs.