Enable analysisd debug in local_internal_options: analysisd.debug=2
Add the following rules on /var/ossec/etc/rules/local_rules.xml
Details
```xml
5700illegal user|invalid usersshd: Attempt to login using a non-existent userT1110.001T1021.004T1078authentication_failed,gdpr_IV_35.7.d,gdpr_IV_32.2,gpg13_7.1,hipaa_164.312.b,invalid_login,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_AU.6,pci_dss_10.2.4,pci_dss_10.2.5,pci_dss_10.6.1,tsc_CC6.1,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,5700illegal user|invalid usersshd: Attempt to login using a non-existent user (Overwrite 1)T1110.001T1021.004T1078authentication_failed,gdpr_IV_35.7.d,gdpr_IV_32.2,gpg13_7.1,hipaa_164.312.b,invalid_login,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_AU.6,pci_dss_10.2.4,pci_dss_10.2.5,pci_ds$,tsc_CC7.3,5700illegal user|invalid usersshd: Attempt to login using a non-existent user (Overwrite 2)T1110.001T1021.004T1078authentication_failed,gdpr_IV_35.7.d,gdpr_IV_32.2,gpg13_7.1,hipaa_164.312.b,invalid_login,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_AU.6,pci_dss_10.2.4,pci_dss_10.2.5,pci_ds$,tsc_CC7.3,5700illegal user|invalid usersshd: Attempt to login using a non-existent (user Overwrite 3)T1110.001T1021.004T1078authentication_failed,gdpr_IV_35.7.d,gdpr_IV_32.2,gpg13_7.1,hipaa_164.312.b,invalid_login,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_AU.6,pci_dss_10.2.4,pci_dss_10.2.5,pci_ds$,tsc_CC7.3,5700illegal user|invalid usersshd: Attempt to login using a non-existent (user Overwrite 4)T1110.001T1021.004T1078authentication_failed,gdpr_IV_35.7.d,gdpr_IV_32.2,gpg13_7.1,hipaa_164.312.b,invalid_login,nist_800_53_AU.14,nist_800_53_AC.7,nist_800_53_AU.6,pci_dss_10.2.4,pci_dss_10.2.5,pci_ds$,tsc_CC7.3,
```
Rationale
We found that Analysisd leaked some memory when overwriting the same rule multiple times, as described at https://github.com/wazuh/wazuh/issues/13505.
Checks