I also had this same issue. To fix it I had to do 2 things.
1.) Create an index named firewall
2.) Add this index to the "Indexes searched by default" section which is under Manager->Access Controls->Roles->Select the appropriate role.
This was done with v 5.0.4 of Splunk
I hope this is helpful.
... View more