I want to create an index in an indexer cluster and pull firewall logs to store in that index.
If the answer solves your issue, do mark it as accepted. If not, do elaborate with more information about your issue.
Getting Data Into Splunk:
http://docs.splunk.com/Documentation/Splunk/6.0/Data/Howtogetgoing
Creating an index in a distributed environment:
https://answers.splunk.com/answers/218464/how-to-create-a-new-index-in-index-cluster-622.html