Hi,
Each IP address generating TCP traffic on one of the ASA interfaces except the lowest security one is considered as a node.
If you have for instance a DMZ, each hosts behind this interface will also be counted as nodes.
If you want to see which IP are using your nodes, you can log at Informational level and look for message 6-421005 in the logs.
It should give you something like this:
%ASA-6-421005: inside: 1.1.1.1 is counted as a user of Content Security and Control Card
Regards,
Nicolas