Thanks, this helped a lot. I had two instances of Spunk and the transforms.conf fixed formatting issue. Without the fix, it was hard to search for source/destination ports and source/destination IPs.
Older version.(After upgrade to version 6.0)
nano /opt/splunk/etc/apps/Splunk_CiscoFirewalls/local/transforms.conf
Newer version.
nano /opt/splunk/etc/apps/Splunk_for_CiscoASA/local/transforms.conf
... View more