Not sure I really understand your question. Cisco ASA is a security appliance, so the data you see in Splunk with this sourcetype usually comes in via TCP from those devices. Splunk has a TA for that with documentation.
But I am really not sure if that's what you are asking about.