To clarify, there are 2 distinct items here: multi-line data, and a multi-value field.
multi-line event: this is a single event that contains multiple lines, which may contain some number of fields, ex: a Java stack trace
multi-value field: this is a single field within an event that may contain more than one value, ex: to_address=bob@example.com,joe@example.com,jane@example.com
The current table renderer that ships with Splunk 4.0+ will render multi-value fields on separate lines, but render a multi-line event as a single line. Obviously the raw event renderer will always show multi-line events with line breaks preserved.
If you want to render multi-line events in a table with line breaks preserved, you can add a CSS rule to the desired table (either via an application.css or other custom CSS file). In the meantime, I will file this as an enhancement request.
... View more