So I am trying to get multiline to work and am doing something stupid. Anyone see anything inherently wrong?

- type: log
- "/var/log/elasticsearch/elasticsearch.log"
  tags: [ "elasticsearch" ]
  multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
  multiline.negate: false
  multiline.match: after

When I got to Kibana and search, it is showing each line as a different item. This is whatever the standard log format for ES is

Could you provide an example log?
Also, have you tried using the elasticsearch module provided by Filebeat:

