getting below errors for continuously in splunkd.log. Is CHECK_FOR_HEADER setting is deprecated in splunk forwarder version 6.5.0?
The CHECK_FOR_HEADER setting is deprecated - INDEXED_EXTRACTIONS should be used instead for file
Detected INDEXED_EXTRACTIONS setting - disabling deprecated CHECK_FOR_HEADER setting for file
My props.conf contains both CHECK_FOR_HEADER and INDEXED_EXTRACTIONS
INDEXED_EXTRACTIONS=CSV
CHECK_FOR_HEADER = true
This setting is deprecated. You can see documentation at https://docs.splunk.com/Documentation/Splunk/8.2.1/Admin/Configurationparametersandthedatapipeline
You can test by removing to see if INDEXED_EXTRACTIONS is enough.
i did not find any solution, No one replied from splunk support either
any resolution for that? I am seeing same errors.