Take attacks that are generating the most alerts (by using the Attack Log page) and investigate their legitimacy. For more information, see Attack Log.
Many of the top alerts seen on the initial deployment of a Sensor will be common false positives seen in many environments. Typically, at the beginning of the tuning process, it will be evident that your network or security policy will affect the overall level of alerts. If, for instance, AOL IM is allowed traffic on the network, there might not be a need to alert on AOL IM setup flows.