I also recommend changing the default SSH port.
IMO best practice is to firewall off everything except some bastion hosts or VPN gateway.
http://bsdly.blogspot.com/2013/02/theres-no-protection-in-hi...
Now the logs are clean from automated login bots, the only thing left are real dedicated hacking attempts that is worth pursuing further.
Doesn't take long to port scan a server.