Surpress False Positives

Thank you @lex
I tried that but I have SALT and it removes them from the threshold.config after the restart.
Do you have example for salt? saltstack/local/pillar/minions/MACHINEID_standalone.sls
In my case most of the alerts are coming from the same host or same subnet. I like to disable/suppress them only for them and rules should stay there. What is the best way to do that?

Thanks again.
Isac