Here is the link to the documentation page for the ES Asset and Identities lookups:
http://docs.splunk.com/Documentation/ES/5.1.0/Admin/Formatassetoridentitylist#Asset_lookup_header
It states for the ip, mac, nt_host, and dns fields:
"A pipe-delimited list of single IP address or IP ranges. An asset is required to have an entry in the ip, mac, nt_host, or dns fields. Do not use pipe-delimiting for more than one of these fields per asset.
So... if I can only use a pipe delimited field for one of those fields, how am I supposed to track assets that have multiple NICs and thus multiple ips and multiple MAC addresses?
What happens if two fields are defined with pipe delimited values?