What does it mean when there is a dash (blank/null?) server ip address for a site?
Seeing this quite often in results and can't seem to find any info online or in other posts here.
That depends on the source - where did this data come from? If the source is a log file, you should be able to find documentation on the log file.
Splunk does not insert any data into the server_ip
field, so the dash/blank/null came from somewhere else.
I assume that you are looking at the events from a Splunk search, so it should be easy to identify the host, sourcetype and source of the events.