In regards to my previous comment about policy configurations:
As for all default rules, customers sometimes are required to tweak the severities to make some rules fire over others if you feel an event should have triggered one rule over another.
And, if customers are seeing false positives, then writing new rules to filter the data may also be required. These tasks are generally being considered as customizations and are to be managed either by customers or our Professional Service team.