Below is an excerpt from an authentication log on a made-up server.
Something happened here that a rate limit would not have caught, because the attacker was patient. Work out which account was actually compromised — not merely attacked — and submit its username as the flag in the form skrd{username}.
Read the log twice. The first pass shows you the noise; the second shows you the one line that is different.