I want to create child decoder of
windows_eventchannel which extract fields from win.eventdata.data
<decoder name="db-mssql">
<prematch>"providerName":"MSSQL\.*",</prematch>
</decoder>
<decoder name="db-mssql">
<prematch>EventChannel.*"providerName":"MSSQL\$</prematch>
<plugin_decoder offset="after_prematch">JSON_Decoder</plugin_decoder>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>"providerName":"(\w+)\$\w+",</regex>
<order>program_name</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>"providerName":"(\.*)",</regex>
<order>providerName</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>"systemTime":"(\.*)",</regex>
<order>systemTime</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>"computer":"(\.*)",</regex>
<order>dbServer</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>"severityValue":"(\.*)",</regex>
<order>severityValue</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\\naction_id:(\w+)</regex>
<order>action_id</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>session_id:(\d+)</regex>
<order>session_id</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>client_ip:(\d+.\d+.\d+.\d+)</regex>
<order>db_rhost</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>session_server_principal_name:(\w+)\\nserver_principal_name|session_server_principal_name:WIN\\\\(\.*)\\nserver_principal_name</regex>
<order>db_user</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>database_name:(\.*)\\nschema_name</regex>
<order>db_name</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\\nstatement:(\w+)</regex>
<order>db_action</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\sstatement:(\.*)\sadditional_information</regex>
<order>db_statement</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\\nduration_milliseconds:(\w+)</regex>
<order>db_duration</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\\naffected_rows:(\w+)</regex>
<order>db_affected_rows</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\\nsucceeded:(\w+)\\n</regex>
<order>execution_status</order>
</decoder>
<decoder name="db-mssql-fields">
<parent>db-mssql</parent>
<regex>\\nobject_name:(\w+)\\n</regex>
<order>object_name</order>
</decoder>