It would be handy if the brute force monitor messages told you which log file(s) showed evidence of hack attempts.
Something like
Something like
A new message or response with subject:
Brute-Force Attack detected in service log /var/log/messages from IP(s) xx.xx.xx.xx
has arrived for you to view.
Follow this link to view it: