Thresholds alone are always either noisy or useless. What helps more is what happens next.
Failures followed by a success from the same source is the alert worth waking somebody for. Failures on their own are background radiation on anything internet facing.
If you want a number, 30 in a minute from one source catches automation without catching humans. Tune per service though, SSH on a public address and an internal app should not share a threshold.
Thresholds alone are always either noisy or useless. What helps more is what happens next.
Failures followed by a success from the same source is the alert worth waking somebody for. Failures on their own are background radiation on anything internet facing.
If you want a number, 30 in a minute from one source catches automation without catching humans. Tune per service though, SSH on a public address and an internal app should not share a threshold.