There is a page that documents the required setup: https://campus.barracuda.com/product/cloudgenfirewall/doc/73719600/splunk-integration/?sl=AWK4o5wZN7f2DU1O40PP&so=2
It's worth noting that there are a few specific settings on the firewall that need to be configured in order for the dashboards to work correctly, in particular:
In "General Firewall Configuration"
* Application Control Logging: Log-All-Applications
* Activity Log Mode: Log-Pipe-Separated-Key-Value-List
If you look at the "Search" app of Splunk, do you see the raw data there?
Hope this helps!
... View more