I think it would be good to have a discussion about this. As I have said to Radu previously, I think it would also be helpful if there was a way for users to flag known anomalous readings due to testing with sources etc so that these are excluded from any alarm algorithm.
6hr is probably a sensible cut off which will exclude short-term artefacts but will not miss a gradually rising trend due to spreading contamination etc. Maybe it would be possible to implement a moving average function which could trigger an alarm if an agreed threshold or a given rate of increase is acheived from more than 1 adjacent stations.
There is another kind of phenomenon which I am interested in (not accident related) which could be flagged by an alarm and that is brief but very large positive excursions in count rate at multiple stations caused by CME or even GRBs. It would be neat if we could capture these events as they happen.