Splunk: Asset and Identity Framework
Merge for Assets or Identities
If you disable the merge only the first asset found will be correlated.
"For example, the asset_lookup_by_str lookup in transforms.conf has max_matches = 1, so the first host it matches in the assets_by_str collection is the only one you'll see in your search results."
show all assets
|datamodel("Identity_Management", "All_Assets")
| rename All_Assets.* as *
| assets
index=_internal sourcetype="identity_correlation:merge" source=*entity_merge.log*