When you say you edited the inputs.conf, was it the main splunk inputs configuration file or was it the inputs.conf for the cicso_firewalls app itself?
If you go to your splunk directories in program files and navigate to \splunk\etc\apps\Splunk_CiscoFirewalls\local , you will see the inputs.conf directly associated with the app. Open that and the default is [udp://514]. Change that to the port that you listed above and restart Splunk again. Since you're forwarding over 2550, the app will start to parse those logs based on the source and you should start to see results for sourcetype="cisco_asa" in your search.
... View more