k them, you must use a bouncer. You can find them on https://hub.crowdsec.net/browse/#bouncers
<code ... wordpress bruteforce"
debug: false
# failed auth on wp-login.php returns 200
filter: "evt.Meta.log_ty... iption: "Detect attempt to access Wordpress files on machine without Wordpress running"
filter: 'evt.M