The rules 33033 often fails on Linux systems with long journals (timeout). An opportunistic enhancement would be to call `journalctl -b --grep protection` instead of `journalctl` to begin with.