Graylog stops showing logs after activating extractor

I have a Panorama firewall sending me logs for possible threats and network traffic.
The messages for threats always contain the match for the regex ^[.*,THREAT,.*] and I created an extractor for extracting all fields, which worked great when testing with the logs I received.
When I finished the extractor and activated it all the logs which the extractor should be extracting ceased to come. Before I had almost 10 logs/second and now I have zero. Checking the firewall it shows the logs keep being sent and deactivating the extractor makes them start being received again.
I believe they are being received by Graylog but I can’t get them on the search anymore, is he discarding them? I am not sure what is happening or could be happening.

