I've noticed this event trigger 8 times on one of my customers IPS devices in the past 24 hours. With the exception of the Summary alert, though, all other alerts had source/destination IPs and was traffic coming in from the Internet.
From what you describe above it sounds to me like you're just seeing Summary alerts. I'm not sure why you wouldn't see the alerts that have source/destination unless there is a filter that disables the alerting for certain RR's.
Jon.