Hi @Coco21
It sounds like you are heading in the right direction to group those hosts and apply a Role Policy to squelch those alarms.
When you show the alarm table, look in the Policy column, this will show you which Policy is being triggered to generate the alarms. You will either need to tune the Policy indicated or remove the hosts from the group that policy is applied to.
There are two classes of policies, Default and Role. Any Role policy supercedes the setting in the Default for the events defined in the policy, but a host with multiple Role Policies is subject to all of them equally.
I hope you find that helpful!
--jg