Yeah, so this thread has been around for 7.5 years and has an accepted answer. The chances of someone seeing your response is very slim. I suggest you post a new question. Reference this one, if you like.
Having said that, you should be able to use a text editor to modify all instances of "WARN" to "INFO" in the $SPLUNK_HOME/etc/log.cfg file. Make a backup first, of course. Restart Splunk for the changes to take effect.
... View more