Yes, you can create a child decoder with json as its parent. There's one thing to watch out for, though. Once json has a child decoder, the event is handled by the matched child only. The parent's JSON_Decoder plugin no longer runs. If your child only has a <regex>, you get your extracted field but lose all the standard JSON fields. Worse, any other JSON log that doesn't match your child ends up with no decoded fields at all.
To avoid this, call JSON_Decoder in your child decoder, add a sibling with the same name for the regex, and add a catch-all child at the end so other JSON logs still decode normally:
<decoder name="json_myapp">
<parent>json</parent>
<prematch>"app":"myapp"</prematch>
<plugin_decoder>JSON_Decoder</plugin_decoder>
</decoder>
<decoder name="json_myapp">
<parent>json</parent>
<regex type="pcre2">"msg":"login user (\w+)</regex>
<order>extracted_user</order>
</decoder>
<decoder name="json_default">
<parent>json</parent>
<plugin_decoder>JSON_Decoder</plugin_decoder>
</decoder>
Result in wazuh-logtest (4.14.0):
{"app":"myapp","msg":"login user alice","src":"10.0.0.1"}
name: 'json'
parent: 'json'
app: 'myapp'
<order>extracted_user</order>
</decoder>
<decoder name="json_default">
<parent>json</parent>
<plugin_decoder>JSON_Decoder</plugin_decoder>
</decoder>
Result in wazuh-logtest (4.14.0):
{"app":"myapp","msg":"login user alice","src":"10.0.0.1"}
name: 'json'
parent: 'json'
app: 'myapp'
extracted_user: 'alice'
msg: 'login user alice'
src: '10.0.0.1'
{"app":"other","msg":"hello","src":"10.0.0.2"}
name: 'json'
app: 'other'
msg: 'hello'
src: '10.0.0.2'
Keep json_default as the last child, with no <prematch>. Please test your own logs with wazuh-logtest before deploying, since these children apply to every JSON event the manager receives.
Regards,