Earlier quoted context omitted.
If somebody has a stolen credential, they aren’t going to be brute forcing at all. Likewise that CVE wouldn’t be attacked by a brute force attack. But I see you’ve backpedaled to this being about log noise, not security.
Threat detection is a higher security priority than prevention in my experience. One may believe whatever they like, as both our intentions are clear friend. Have a wonderful day =3
The roving spam it blocks are not threats, and stolen credentials aren't going to be detected by it.