Said It Here

Why is security software generating so many false alerts?

Endpoint security software frequently creates severe alert fatigue by flooding systems with thousands of noisy warnings and heavy CPU usage. This constant disruption causes system performance issues, conflicts with background services like the search indexer, and forces administrators to repeatedly restore servers from backups.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Replacing the endpoint security software with alternatives like Huntress combined with Windows Defender or Defender for Endpoint (DfE)
  2. 2
    Creating policy overrides, exclusions, and custom rules to attempt to stop alert fatigue

In their words

Unedited, most upvoted first, each linked to the thread it came from.

No product is perfect but after having to restore servers from backup several times and the Dell software generating thousands of alerts despite an S1 "mitigation" I've had enough.source ↗

cokebottle22 · r/msp · 31 upvotes

We started doing this last year.. S1 blowing up our RMM with no explanation or fix from S1.source ↗

Hawk947 · r/msp · 1 upvotes

I too am getting frustrated with the noise that is S1. Constant CPU and disk hog and conflicts with the search indexer service.source ↗

Skrunky · r/msp · 1 upvotes

Where this came up

People with this problem also raised