Can't see messages from Fortigate

I have new graylog 2.2.1 installation on ubuntu server 16.04. It works fine with all of our network devices but when I enabled logging from our fortigate cluster I can’t see those logs. Graylog is processing messages from fortigate I see significantly grow of In and Out messages so messages are processed, but I can’t see those logs in sources or cat’t search it. Where could be the problem?

Try using a Raw/Plaintext input and extract the fields relevant for you with extractors or processing pipeline rules.

Plaintext helped. Now I need to build some extractors. Thanks for help!

