Splunk Search

User Preferences

wpreston
Motivator

How and where does Splunk store user's preferences (like selected fields, last used time range, that kind of thing)? What permissions are needed to create or modify whatever files are used for this?

Tags (1)
0 Karma

jtrucks
Splunk Employee
Splunk Employee

They are in $SPLUNKHOME/etc/users and owned by the splunk user.

--
Jesse Trucks
Minister of Magic

wpreston
Motivator

Great, thank you for your answer! I found a file called UI Prefs.conf and it does have the fields selected by the user. However, the user's selected time range is not in that file. What file is that stored in? I looked around at all the files in my user's directory and didn't see it anywhere.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...