i'm new to splunk
i'm having the same issue as https://answers.splunk.com/answers/24484/sql-server-errorlog.html#answer-746299, i have tried
[sqlserver_errorlog]
CHARSET = UTF-16LE
NO_BINARY_CHECK = true
on my UF and indexer with no luck. however, i think i might updating wrong props.conf
what is the right path for props.conf on both UF and indexer please.
Thank you in advance