Is there any recent doc on how Splunk imports csv files with headers? I see a lot of questions, and the answers are all over the place. This shouldn't be difficult...
you mean, besides this?
http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/Extractfieldsfromfileheadersatindextime#Examp...
as the topic mentions, CHECK_FOR_HEADER has been deprecated in 5.x, but it does work.