I figured out my question after posting so posting for others to read and for Box to update their documentation to help others on the Splunk Cloud.
Go to Settings and Lookups
Select Lookup table files
Select Box App for Splunk under the App context and you will see the path of the domains.cvs shown below
Create a csv in Excel with cell A1 = corp_code and cell B1 = corp_domain
Enter the domains 1 per row in column B
Enter the number 1 in reach row in column A where you have a domain in B
Save the file as a csv
Click new
Browse for the domain.csv you just created and name it domains.csv. You will see 2 paths listed with the one you just uploaded as Private under sharing.
Delete the Global domains.csv and you should see only the one you uploaded.
Click on Permissions
Change to All Apps and grant Everyone Read and Write and click save
Now the Box for Splunk app should read in your domains.csv file on Splunk Cloud to accurate display non-corp logins and events on the dashboards.
... View more