Graylog version: 2.4
Elasticsearch version: 5.6.8
Create indice for Squid. In System / Indices. The index prefix must be squid as the image show. This is important for the proper functioning of the streams.
Content Pack
Import de file in forder Content Pack and upload it.
Select squid from the list
And apply the content
Edit squid stream and select the index previusly created.