You have mentioned that you have deployed the app via Search head cluster deployer which is fine, but you need to copy indexes.conf and props.conf from default folder on the app to indexers and in case of indexer cluster to this directory $SPLUNKHOME/etc/master-apps/cluster/local/ on cluster master, then run "splunk apply cluster-bundle".
This is because indexed extractions need to be applied during indexing time.
Structured Data Header Extraction and configuration
* This feature and all of its settings apply at input time, when data is
first read by Splunk. The setting is used on a Splunk system that has
configured inputs acquiring the data.