# Auditbeat Errors - Do Not Pass Go Do Not Collect $200

**URL:** <https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [October 30, 2018, 1:22am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539 "2018-10-30T01:22:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jc034240](https://avatars.discourse-cdn.com/v4/letter/j/977dab/32.png) [@jc034240](https://discuss.elastic.co/u/jc034240)\
**Post date:** [October 30, 2018, 1:22am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539/1 "2018-10-30T01:22:19Z")

</div>

What's the rule on spacing? Below are two different spacing scenarios and the related errors for logstash as an output.

```
#----------------------------- Logstash output --------------------------------
# Zero space in front of "output.logstash:", 2 spaces in front of all #subsequent settings
> output.logstash:
> enabled: true
> hosts: ["x.x.x.x:1234"]
> worker: 32
> compression_level: 3
> escape_html: true
> pipelining: 5
> max_retries: -1
> bulk_max_size: 8192

```

Command  
sudo auditbeat setup --template -E output.logstash.enabled=false

Error  
Exiting: error loading config file: yaml: line 137: did not find expected key

```
#----------------------------- Logstash output --------------------------------
# 1 space in front of "output.logstash:", 3 spaces in front of all # #subsequent settings
> output.logstash:
> enabled: true
> hosts: ["x.x.x.x:1234"]
> worker: 32
> compression_level: 3
> escape_html: true
> pipelining: 5
> max_retries: -1
> bulk_max_size: 8192

```

Command  
sudo auditbeat setup --template -E output.logstash.enabled=false

Error  
Exiting: error initializing publisher: No outputs are defined. Please define one under the output section.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 30, 2018, 1:27am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539/2 "2018-10-30T01:27:08Z")

</div>

It's yml so it should be 2 spaces.

But if you can reformat things using the `</>` (aka code) button, or use markdown style back ticks, then it'd really help 🙂

---

<div class="post-metadata">

**Author:** ![jc034240](https://avatars.discourse-cdn.com/v4/letter/j/977dab/32.png) [@jc034240](https://discuss.elastic.co/u/jc034240)\
**Post date:** [October 30, 2018, 1:37am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539/3 "2018-10-30T01:37:31Z")

</div>

To clarify - for Logstash output; should the first line that begins with "output.logstash:" have zero or 1 space in front of it?

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [October 30, 2018, 2:34am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539/4 "2018-10-30T02:34:02Z")

</div>

Zero spaces before any "top level" blocks like `logstash.output`, and add 2 spaces for each additional nesting level.

The installed Auditbeat comes with a config file with good defaults ([or check it out on GitHub](https://github.com/elastic/beats/blob/master/auditbeat/auditbeat.reference.yml)) and some of the most commonly used options commented out. The convention for commented out sections is `#` (pound sign and no spaces following it). If you uncomment by always removing the pound sign without re-adding spaces, everything should be nested correctly.

So you're almost there. The following should do it:

```auto
output.logstash:
  enabled: true
  hosts: ["x.x.x.x:1234"]
  worker: 32
  compression_level: 3
  escape_html: true
  pipelining: 5
  max_retries: -1
  bulk_max_size: 8192

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2018, 2:34am UTC](https://discuss.elastic.co/t/auditbeat-errors-do-not-pass-go-do-not-collect-200/154539/5 "2018-11-20T02:34:03Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
