This is super simple you just need to create your transforms and update the props.conf. I recommend you read Routing and and Filter data http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Routeandfilterdatad. This needs to be done on the indexer or heavy forwarder.
#Transform
[PIX_Index]
DEST_KEY = _MetaData:Index
FORMAT = PIX
REGEX = %PIX-\d-\d{6}
[FWSM_Index]
DEST_KEY = _MetaData:Index
FORMAT = FWSM
REGEX = %FWSM-\d-\d{6}
[ASA_Index]
DEST_KEY = _MetaData:Index
FORMAT = ASA
REGEX = %ASA-\d-\d{6}
Now update your props.conf.
#props.conf
[source::tcp:514]
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm,PIX_Index,FWSM_Index,ASA_Index
[source::udp:514]
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm,PIX_Index,FWSM_Index,ASA_Index
[syslog]
TRANSFORMS-force_sourcetype_for_cisco = force_sourcetype_for_cisco_asa,force_sourcetype_for_cisco_pix,force_sourcetype_for_cisco_fwsm,PIX_Index,FWSM_Index,ASA_Index
... View more