We have recently set up SOC monitoring for our R80.40 Gateways. There have been constant alerts related to excessive denies from a single source or excessive prevent action logged by IPS.
My query is if the action is drop/reject or prevent for either neutral reputation or malicious reputation... are these kind of alerts relevant enough to be addressed or they are best left unattended considering Firewall on its own is taking care of these.
Or do i need to worry about Firewall Health or look at if a certain benchmark has been breached from a single source . for example : if there are more than150k or 100k hits from a single source then i should check certain things such as Firewall Health , Memory etc. ?