You can use the groupby parameter to group multiple fields referring to the same type of activity into a single alert, instead of multiple alerts. For example, you create a rule that detects RAR files being transferred over the network, but you do not want an alert each time a RAR file is transferred from the same host. If you add srcipv4 (the source IP field) to the rule, then only one alert is generated for each host sending RAR files.
For more information on how to use the groupby parameter, see the example rules in Understanding the rule language.