The answer is the time required depends on a number of factors: snort
ruleset, number of hosts/nets monitored, and level of treatment given to
each incident.  You can greatly reduce the time involvement per incident
by using a nice web front end (I use acid) and database backend
(PostgreSQL) that will allow you to drill down on an incident and quickly
find out more information about the offending IP and what other nefarious
things it has done to your network.

Also, keep in mind that even on a well configured snort system, you may
get alerts faster than you can process them.  It will take some time for
you to get used to your own environment and filter out the noise from the
really bad stuff and then tune your ruleset and/or firewalls accordingly.
This is an ongoing process.

