Snort provides a variety of mechanisms to tune event processing to suit your needs:
You can use detection filters to specify a threshold that must be exceeded before a rule generates an event. This is covered in section 3.7.10.
You can use rate filters to change a rule action when the number or rate of events indicates a possible attack.
You can use event filters to reduce the number of logged events for noisy rules. This can be tuned to significantly reduce false alarms.
You can completely suppress the logging of unintersting events.