Springboarding off the jcoates reply: Splunk defers index creation, management, routing, and use to the Splunk administrator.
It appears that your Splunk instance was successfully customized to route firewall data to a specific index. This is fine and good (and documented).
Yet Splunk's User role, by default, only searches the main (default) index. When data is routed to a custom index, users will not be able to implicitly search it until it is included among the default search indexes (step #7). Per your original post, it can be explicitly referenced in the search (provided it is also allowed to do so, per step #8)
... View more