I put on my firewall a block for incoming traffic for all IPs outside Europe which helped a lot with the quantity of attempts.
is it possible? how did you filter? (I've tried 2 years ago: at that time even aws is not able to provide a reliable EU ip list)
A custom fail2ban jail adds all IPs that get blocked by the Tcp Wrappers to the system's firewall.