How and where does Splunk store user's preferences (like selected fields, last used time range, that kind of thing)? What permissions are needed to create or modify whatever files are used for this?
They are in $SPLUNKHOME/etc/users and owned by the splunk user.
Great, thank you for your answer! I found a file called UI Prefs.conf and it does have the fields selected by the user. However, the user's selected time range is not in that file. What file is that stored in? I looked around at all the files in my user's directory and didn't see it anywhere.