I am using index=pcf and I am getting plenty of events. The documention says that the following sourcetypes are configured automatically but those parameters show up in my search as event_type.
Firehose event type Splunk sourcetype
Error cf:error
HttpStartStop cf:httpstartstop
LogMessage cf:logmessage
ContainerMetric cf:containermetric
CounterEvent cf:counterevent
ValueMetric cf:valuemetric
From the ingested events, it appears that I am getting all the events that would be needed to populate the dashboards in the Add-on for Cloud Floundry