Splunk Search

User Preferences

wpreston
Motivator

How and where does Splunk store user's preferences (like selected fields, last used time range, that kind of thing)? What permissions are needed to create or modify whatever files are used for this?

Tags (1)
0 Karma

jtrucks
Splunk Employee
Splunk Employee

They are in $SPLUNKHOME/etc/users and owned by the splunk user.

--
Jesse Trucks
Minister of Magic

wpreston
Motivator

Great, thank you for your answer! I found a file called UI Prefs.conf and it does have the fields selected by the user. However, the user's selected time range is not in that file. What file is that stored in? I looked around at all the files in my user's directory and didn't see it anywhere.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...