If you do a (distinct)count of something and there are no matching events, the result is 0. This is expected behavior imho. Actually there's a very important distinction to make here. Suppose I ask you, "How many balls are inside the box in the next room?" Consider two scenarios: You walk into the next room, see the box, look inside, and see nothing. You walk into the next room and see nothing. No box, no balls; nothing. These are clearly not the same scenario, and so I would expect different behavior imho. Intuitively, a human would likely respond along the lines of "Zero!" "Uhm... there is no box!" The fundamental issue is that any feasible response to a question implicitly validates the premise(s) of the question. In case 2, we need Splunk to return a result indicating our premise is false. Indeed, the "null value" config exists, at least in part, to make this distinction... assuming it works 😉
... View more