Block ip once after 5 incorrect logins in 10 minutes

I would like to be able to set my own failed login rules to 5 incorrect logins in 10 minutes from an ip address for a user. Anomaly detection is 10 failed logins from the same ip address for a user. Basically a way to customize anomaly detection to meet what I want.

1 Like