Based on your inputs, I am putting few ways where it might have gone wrong.
There is no data in D:\Syslog\ASA. But as you said, there is data.
Check the user splunk running with, does he have permission to access D:\Syslog\ASA
On indexer, there is no index created with the name cisco_asa. In such case, the indexer will throw warnings that there is data coming for this index which in not present.
The most common mistake, the data is perfectly indexed in index=cisco_asa but, the User Role you are logged in with does not have 'cisco_asa' index added to searchable list. Using Admin user, Please visit Settings >>> access control >>> [your user role] >>> check the list of indexes allowed to be searched for your role.
Above are some causes that make some indexed data not searchable. Please do a check and revert.
... View more