I think the issue here is not the tricky syntax (IMHO, it can be a bit complex when you want to drill into nested structures, but for top-level JSON fields it is pretty straight forward). In other words: the syntax seems to be correct, but I guess the problem is a known issue: the field “VehType” is not present in all events, but it was added after some time, i.e. there is a non-neglectable number of events without “VehType” and then new events with the field.
Dremio (the internal engine in CDH) has learned the MongoDB schema without “VehType” and thus it is required to trigger schema learning again. Unfortunately, this is not a function you can run from the UI, but you need to run an external script (Sign in to your account) and need an admin account for Dremio. The script is run like that (documentation is contained in the ZIP file):