The example dashboards process Audit Journals to populate search results and visualizations. This data can be stored in one or more Splunk indexes.
Refer to the Ironstream Integration Components Administration Guide for details on how to configure Ironstream to allow a Splunk index to be populated with these data types.
The Starter Pack’s Documentation menu includes a link to an informational dashboard named Ironstream Configuration Settings, which provides descriptions of all the Audit Journal entry types used by the dashboards.