FYI: You should create a new question, not post an answer to an existing question.
I believe the problem you are facing is the fact that you do not have the Cisco Networks Add-On for Splunk installed on your search head and indexers. This would explain why we are not seeing any fields extracted. Either that or you changed the permissions of the app's objects to not be exported globally.
You need both the App and Add-on on the search head. The indexer needs to Add-on.
You will need to restart the server after you install the apps/add-ons before they come into effect
... View more