I would agree with wingfieldj, check the configuration files for the ASA forwarder and see where the logs are being forwarded too, making sure it matches the indexer you are querying.
Another random guess is that make the bucket size maybe maxed/capped out, if your Splunk indexer can only hold a certain amount of data, the forwarder may send logs all day but based may either be reaching the indexer much delayed. I highly doubt this because you should have at least some sort of data indexed from the ASA but just giving a wide shot thought.
But check the configs on both the forwarder and the indexer and if it matches, then look into the dropped data possibility.
... View more