Have you tried the Splunk for Cisco Firewalls app on splunkbase? It will have extractions, views etc already done for you? Even if you don't want the app if you install it and look in the default/props.conf you'll see regex for extracting data you are looking for.
http://splunk-base.splunk.com/apps/22303/splunk-for-cisco-firewalls
You can also use the interactive field extractor within splunk to generate the regex - http://docs.splunk.com/Documentation/Splunk/latest/User/InteractiveFieldExtractionExample
At search time you can use the 'rex' command to create field values if that's what you meant by inline.
... View more