null is not a reserved word in Splunk. So your solution may appear to work, but it is actually testing
field!="null"
In the search command, the text following an equal sign is considered a string.
But it probably works in your application.
... View more