I have bluecoat logs following this naming convention:
SG_main__21_1117054549.log.gz.done
When I import logs into FA, small logs are processed fairly quickly while larger logs take several minutes to process. This isn't a problem, I am a patient person :)
However, the problem is that after logs are imported I am unable to see any data or reports based on log data. I know there are valid records in the logs as on the import logs page it shows how many records. After importing the logs, I have a "squid proxy server" object with IP of 127.0.0.1 that I can generate reports from. I assume this corresponds to the BlueCoat logs that I've imported.
The question is -- how do i make FA properly recognize and report on the bluecoat logs?