Tune the hell out of your sensors and eliminate as many false positives as possible before going into production. Then tune them some more. Get important people to sign off on the tuning. If you’re using IPS, make sure that your blocking signatures have been tuned and will not block legitimate traffic. You may have to write custom signatures for your own environment. Make sure that any custom signatures you write are well documented. The very last thing you want is people being woken up in the middle of the night for false positives – they will seek revenge.