We investigate people and assets, not just IPs. Splunk ES uses the Asset and Identity (A&I) framework to automatically enrich logs.
If an alert fires for 10.0.0.5, A&I lookups tell you if that IP belongs to an Executive's laptop or a critical database server, changing the priority instantly.