I have FileBeat running with the multiline option feeding Logstash with a grok filter and everything seems to parse properly and ingest into Elasticsearch fine. The problem is display in Kibana. I have a pie-chart that displays logger and logmessage fields but those loggers associated with an error loglevel (all of which are stacktraces) appear to have no logmessage - but the Discover tab does show those events as having a multiline logmessage. I have another visualization on my dashboard, a data table, that just shows logmessages. When I drill down on the pie-chart to filter to error level events, the data table also becomes empty.
Does kibana have trouble displaying multiline values? I think I expect to see the first few words truncated to display area.