How can I view the default index of a user?
In other words, if user runs a search within splunk search app and does not specify an index, how do i view which index he will default at?
Check the user's role. That role may have one or more default indexes defined. A search that doesn't specify an index will look in all of the defined default indexes.