In Splunk Enterprise Security, searches don't look for specific sourcetypes like "cisco:asa". Instead, they look at the Common Information Model (CIM) datasets.
If your data isn't mapped to the CIM (e.g., aliasing `src_ip` to `src`), ES correlation searches will be blind to it.