unless you really need it (constantly under attack/want to get rid of bots at all costs), I wouldn't recommend keeping it on, yea. Espec if your site is static and you can just cache pages and not worry about attacks as much. It also just won't be effective at all if you have an API for example, just have to disable it entirely at least on that subdomain (need sbfm for that of course), it's just going to false positive and cause issues, meant for web/user traffic