Community Apps are supported by the free license: http://www.splunk.com/view/free-vs-enterprise/SP-CAAAE8W
As araitz suggested, please ensure your Bluecoat data is sourcetyped as
bcoat_proxysg. Additionally, you will need to ensure the field extractions match your particular bluecoat log format. This is likely the culprit and the trickiest part to adjust if you are new to Splunk.
If you want, please paste your Bluecoat logging format here and we can help you with the field extraction configuration.
The Splunk for Bluecoat app should work on the free version of Splunk, provided you are not going over the maxed index per day limit, which is 500mb. You should be able to download and install the app from splunkbase, but you will be required a valid login, which is also free.
Interesting, thanks for the tip. Seems confusing that this wording is used: "Free for use with a Splunk license.". Doesn't every splunk release come with at least a free license or am I missing something?