That depends on the source - where did this data come from? If the source is a log file, you should be able to find documentation on the log file.
Splunk does not insert any data into the ClientIPs
field, so the dash/blank/null
came from source log file. If it's a custom log file then you should contact developer. If it is a standard log file then look for the documentation.
I assume that you are looking at the events from a Splunk search, so it should be easy to identify the host, sourcetype and source
of the events.
I hope this solves your query now!