Try something like this, but do read the VRDs too...
!
ap wired-ap-profile "split-tunnel-port"
wired-ap-enable forward-mode split-tunnel
switchport access vlan x
!
ap wired-port-profile "split-tunnel-port-rules"
wired-ap-profile "split-tunnel-port"
aaa-profile "ROLE-WITH-SPLIT-TUNNEL-RULES"
!
ap-group "YOUR-GROUP"
enet1-port-profile "split-tunnel-port-rules"
!
The bits in capitals obviously you need to work out!