Is It Possible to Use a Child Decoder with the Default JSON Decoder?

20 views
Skip to first unread message

Mithun Haridas

unread,
Oct 8, 2026, 2:11:44 AM (3 days ago) Oct 8
to Wazuh | Mailing List
Hi,

I would like to know whether it is possible to create a custom decoder to extract a specific field from logs that are already being decoded by the JSON decoder, without using the plugin_decoder function. Specifically, can a custom child decoder be created by setting json as the parent decoder and then extracting additional fields? Is this approach supported?

Regards,

Miguel Ángel De la Vega Rodríguez

unread,
Oct 8, 2026, 4:19:45 AM (3 days ago) Oct 8
to Wazuh | Mailing List
Yes, you can create a child decoder with json as its parent. There's one thing to watch out for, though. Once json has a child decoder, the event is handled by the matched child only. The parent's JSON_Decoder plugin no longer runs. If your child only has a <regex>, you get your extracted field but lose all the standard JSON fields. Worse, any other JSON log that doesn't match your child ends up with no decoded fields at all.

To avoid this, call JSON_Decoder in your child decoder, add a sibling with the same name for the regex, and add a catch-all child at the end so other JSON logs still decode normally:

<decoder name="json_myapp">
  <parent>json</parent>
  <prematch>"app":"myapp"</prematch>
  <plugin_decoder>JSON_Decoder</plugin_decoder>
</decoder>

<decoder name="json_myapp">
  <parent>json</parent>
  <regex type="pcre2">"msg":"login user (\w+)</regex>
  <order>extracted_user</order>
</decoder>

<decoder name="json_default">
  <parent>json</parent>
  <plugin_decoder>JSON_Decoder</plugin_decoder>
</decoder>

Result in wazuh-logtest (4.14.0):

{"app":"myapp","msg":"login user alice","src":"10.0.0.1"}
      name: 'json'
      parent: 'json'
      app: 'myapp'
  <order>extracted_user</order>
</decoder>

<decoder name="json_default">
  <parent>json</parent>
  <plugin_decoder>JSON_Decoder</plugin_decoder>
</decoder>

Result in wazuh-logtest (4.14.0):

{"app":"myapp","msg":"login user alice","src":"10.0.0.1"}
      name: 'json'
      parent: 'json'
      app: 'myapp'
      extracted_user: 'alice'
      msg: 'login user alice'
      src: '10.0.0.1'

{"app":"other","msg":"hello","src":"10.0.0.2"}
      name: 'json'
      app: 'other'
      msg: 'hello'
      src: '10.0.0.2'

Keep json_default as the last child, with no <prematch>. Please test your own logs with wazuh-logtest before deploying, since these children apply to every JSON event the manager receives.

Regards,
Reply all
Reply to author
Forward
0 new messages