Device is in place, what do I do next?
Tuning – the time period when you look at your events and weed out any false positives and modify signatures.
Best practice is at least 15-30 days of looking at traffic on a daily basis.
This will enable you to filter out signatures that are “noisy” and see events that show valid attacks.
Once tuning period is over, put the device into block “IPS” mode.