Need help - Cisco syslog events matching in GROK debugger but not showing up in

Why are you setting document_type? That option is deprecated and will be removed, I would guess in 8.0. If this is not the same on every document then documents will get rejected.

I would expect you to be getting the warning and exceptions posted here.