Guess Should work via Aliasing - Below Notes from Cisco Spunk SIEM Doc
The Cisco App add-on will rename the sourcetype of your firewall events to cisco_firewall. If you have previously added Cisco Firewall data as a data source and would like to preserve the current sourcetype for reporting purposes, you can create an alias in the local directory of this app.
Create a sourcetype alias, add the following entry to props.conf under the
local directory of this app ($SPLUNK_HOME/etc/apps/cisco_firewall_addon/local):
[cisco_firewall] rename = your_current_firewall_sourcetype
... View more