The JSON part to extract is MESSAGES. We created a REGEX which works in the search, but it should be also added permanently to this "transforms.conf" file.
Our solution, which didn't work, is:
DEST_KEY = MetaData:Message
First, us there a particular reason you are wanting message to be a metadata field? I believe it can be as simple as this...
Updated to add a simpler version, and to use [^\"]* instead of .* to avoid backtracking.
Refer to this one for a little more instruction, including more steps if you want it indexed: https://answers.splunk.com/answers/171148/how-to-write-regex-to-extract-and-index-a-field-en.html
Second, do you want index time or search time extraction?
Here's some discussion about those considerations: