Looks for an unusually large spike in successful authentication events from a particular source IP address.
Description
Looks for an unusually large spike in successful authentication events from a particular source IP address. This can be due to password spraying, user enumeration or brute force activity.