That doesn't look to me like it would find many real credentials. It is collecting the credentials that automated bots are trying to use, some of them, perhaps many of them, will be credentials that someone somewhere is using for something, but unless you are planning an Internet wide scan yourself using those credentials to try login to something is likely to be fruitless.
I worked at a place that had a lot of baremetal machines on the open internet.
I would occasionally scan the auth.log to see which users the bots were using and it was an interesting mix of:
- service accounts e.g. mysql, admin, etc
- individual names e.g. tom, ankit, alexei etc