Splunk Dev

Why does fillnull command have two type processing? (distributable streaming command/dataset processing)

munang
Path Finder

Splunk documentation said


"fillnull command is a distributable streaming command when a field-list is specified. When no field-list is specified, the fillnull command fits into the dataset processing type"

 

I wonder why it works as dataset processing if no fields are specified. The results are all the same anyway, but there must be a reason.

Thanks for letting us know.

0 Karma

munang
Path Finder

Thank you!!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When a field name is specified, it's easy for an indexer to see that the field has no value and substitute the fill value.  Without a field name specified, it has to know the full set of fields to know which have null values.  That's not a distributable function.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...