This actually not true, see my relevant comment in SAML AD ADFS yaml settings, troubleshooting and role mapping notes and insight (Solved) - #2 by ikakavas
Most errors are returned from Elasticsearch to Kibana as Exceptions so if one has only access to kibana logs, setting logging.verbose: true
in kibana.yml will make sure that enough information will be printed there to start the troubleshooting. But in general, you are correct, ES logs are much more useful as the core of the SAML implementation is in Elasticsearch