Extractor.json contains all the extractors needed to construct fields out of barracuda firewall syslog messages.
In order to import:
- Click 'System' menu and select 'Inputs'
- On a syslog input section, click 'Manage extractors'
- Click 'Actions' button (top right) and select 'Import extractors'
- Copy and paste contents of extractor.json into the text field and click 'Add extractors to input' (below field)
Graylog team has said that importing extractors will be deprecated in favor of content packs which will include extractors along with dashboards and inputs to tie together.