So I begin creating some watcher alerts, and my first script is for detecting brute force using winlogbeat. Here is my script:
PUT _watcher/watch/brute_force_