For a SIEM to be effective, it needs context. The **Asset and Identity** framework merges HR databases (identities) and CMDBs (assets) into Splunk.
When an event fires, ES uses lookups to enrich the event: translating `10.0.0.5` to `web-server-prod` and `jsmith` to `John Smith (VP Finance)`.
This context allows for dynamic urgency rating. An attack on a VP's laptop is higher urgency than an attack on a guest WiFi device.