Assuming your json is properly formatted, try setting KV_Mode=json in your props.conf file against that sourcetype. It should automatically extract the field values from the json events.
You can read more about it here:
https://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf
Let me know if that helps.
... View more