Yes that’s mainly the reason i wish to completely ban the IPs. Besides the login page, there are still thousands of other hits to xmlrpc.php, and the same actor attempting wp-login is also brute forcing xmlrpc.php so it makes sense to ban both.
The original issue still remains, tho, new filter is reporting all zeros, even with a direct log path without wildcard.