SSH Brute Force Attempts

Detects multiple failed SSH login attempts from a single source IP address, indicating a potential brute force attack. The rule identifies 'Invalid user' or 'Failed password' messages in syslog from the 'sshd' process and groups them by source IP and time to count unique attempted users and total attempts. A threshold of more than 5 attempted users from a single source IP within a 10-minute window triggers an alert.