Splunk Dev

Why does fillnull command have two type processing? (distributable streaming command/dataset processing)

munang
Path Finder

Splunk documentation said


"fillnull command is a distributable streaming command when a field-list is specified. When no field-list is specified, the fillnull command fits into the dataset processing type"

 

I wonder why it works as dataset processing if no fields are specified. The results are all the same anyway, but there must be a reason.

Thanks for letting us know.

0 Karma

munang
Path Finder

Thank you!!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When a field name is specified, it's easy for an indexer to see that the field has no value and substitute the fill value.  Without a field name specified, it has to know the full set of fields to know which have null values.  That's not a distributable function.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...