Well that's properbly not the root cause.
I would start by looking after rules that flood the ePO with events. From the scenario described, it could be just about anything
We found the lock ups were unrelated. Our lockups were an Automatic Response to DLP events, notifying us by e-mail when an attempt occured. Turned out, the filters in place for that event were doing some of the same filtering over and over again, locking up the server.
We're sticking with 3 rulesets or less for IPS rule assignment instances anyway. IPS exception and rule edits aren't taking very long.