Cisco eStreamer eNcore Add-on for Splunk v3.6.8 has two EXTRACTs with errors in them.
EXTRACT-extractsrc and EXTRACT-extractdest both have an extraneous equal sign (=) before the start of the regex which means that srcip and destip don't get extracted. Both are under the [cisco:firepower:syslog] stanza.
I stumbled across the same thing today. Additionally i was wondering, if the regex itself has a mistake aswell. Our Firepower generates logs with the fields SrcIP and DestIP. However, the regexes only match a lowercase "p" at the end.