Here's how I set it up.
On the Watchguard, I set it to send syslog to my splunk indexer.
In Splunk, I setup an index called wg (index screenshot).
In Splunk, I setup a Data Input >> UDP to listen on 22514; Manual source type: watchguard:firebox:syslog. Under More settings I set the hostname and Index to wg and specified the only IP to accept syslog input from (eg. the Watchguard cluster). (Data_Inputs screenshots).
Index Screenshot
Data_Inputs Screenshot
... View more