I got the Splunk for Blue Coat ProxySG app and it's working properly. All the dashboards and reports are working perfectly. However, the Splunk TA for Blue Coat is not mapping the fields. In fact, even the Blue Coat fields are not visible outside the context of the Blue Coat App. I checked the permissions on the app objects and they seem OK.
This sounds like permissions. Check app's object permissions in introspection_generator_addon.
I had the same issue, and yes it was permission issue => Go to "Manage Apps" - "View objects" for Blue Coat app and change sharing permissions
Try to check the log format from bluecoat proxy.
It's Bluecoat reporter main.
Even though its BC SG Main format may be admin has changed the format of the logging. Need to check the Props file of TA on what type of format it is referring and check back in Bluecoat SG Main settings for the same.
I mentioned above that the Splunk App for Bluecoat ProxySG is already recognizing the log, as per the app documentation we setup a TCP source and set the sourcetype to bcoat_log. In the app the data show up as bcoat_proxysg with all the fields in the right place. The problem is that, out of the app's context, none of the fields are visible.