I found just using a different port was enough for me and didn't need port knocking to reduce log noise, which I agree is super important.
I also have alerts for both failed SSH or failed wireguard connections, and for any logins from a new IP with either SSH or wireguard.