Parsing don't always occurs at the same place depending of your architecture. If you have UF,HF,IDX and SHC it is more spread. You were missing the CSV settings it's only preparsing. Most of the other settings (date, line breaking, etc) are on the IDX. It's a bit of error and trial.
You can follow this wiki, it is mostly accurate. https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F
It doesn't hurt to have the same props settings everywhere. Just don't do that with indexes.conf, server, etc. Also, _internal is a great source to TB shoot that.
Cheers
... View more