Okay. I've lost half a day and I'm at my wits end trying to trace this down in the logs. I'm a Cisco guy but not strong in wireless. Anything looks familiar to anyone who knows what this crap means? (See Attached)
So it was really due to bad monitoring and reporting all along. Cisco TAC also confirmed my findings. Port-channel was enabled on the interface and the monitoring software was reading the traffic for a single interface. Doubled the threshold and the alerts went away. Thanks for the suggestions.