Your SOC team is drowning in 500+ duplicate alerts per hour for brute force login attempts. You need to redesign the alert to be actionable.
Apply throttling on `src_ip`, consider switching from real-time to scheduled, and think about which alert action (webhook to SOAR, email to on-call) is most appropriate.