Splunk Search

User Preferences

wpreston
Motivator

How and where does Splunk store user's preferences (like selected fields, last used time range, that kind of thing)? What permissions are needed to create or modify whatever files are used for this?

Tags (1)
0 Karma

jtrucks
Splunk Employee
Splunk Employee

They are in $SPLUNKHOME/etc/users and owned by the splunk user.

--
Jesse Trucks
Minister of Magic

wpreston
Motivator

Great, thank you for your answer! I found a file called UI Prefs.conf and it does have the fields selected by the user. However, the user's selected time range is not in that file. What file is that stored in? I looked around at all the files in my user's directory and didn't see it anywhere.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...