We have a customer that has two Box tenants for legal separation but would like to use a single Splunk instance for event tracking. A previous question in 2016 asked a question which hinted that it might be a future addition. Has it been added and if not, is there a way to have two Box tenants feed 1 Splunk instance? What would the box add-on deployment look like?
For your case, you can configure box addon on 2 different Splunk instance using different box account.
Means now you have a 2 data collection Splunk instance which will forward the data to the single Splunk indexer Instance. This will allow searching box events from single Splunk Instance.