# Can't figure out source of config error in new filebeat module

**URL:** <https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [July 23, 2018, 7:55am UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102 "2018-07-23T07:55:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![per.fagrell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/per.fagrell/32/33596_2.png) [@per.fagrell](https://discuss.elastic.co/u/per.fagrell)\
**Post date:** [July 23, 2018, 7:55am UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/1 "2018-07-23T07:55:04Z")

</div>

I've just walked through the documentation on creating a new filebeat module, tested my parser with the simulation API and then copied the files over to a docker container and fired it up. However, when it loads the module I'm getting a pretty unhelpful error:

> |2018-07-23T07:30:53.697Z|INFO|log/input.go:113|Configured paths: [/opt/orderpages-server.log\*]|  
> |---|---|---|---|  
> |2018-07-23T07:30:53.697Z|INFO|input/input.go:88|Starting input of type: log; ID: 16991430678465977839|  
> |2018-07-23T07:30:53.698Z|ERROR|cfgfile/reload.go:232|Error loading config: invalid config: yaml: invalid map key: map[interface {}]interface {}{"module":interface {}(nil)}|

Which config file is this referring to? That serverlog is the one my module is configured to pick up, so it seems intuitive that my module isn't quite right. I've checked all the .yml files in my module, I've copied over the modules.d/passion.yml.disabled, and I've run 'make update' and put the kibana/{5,6} files in the right place, etc. Would be nice if the error could give a hint as to the path it died on.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [July 23, 2018, 10:10am UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/2 "2018-07-23T10:10:04Z")

</div>

Could you share your configuration file? Also the directory tree of your module?  
Also, does this happen when you run Filebeat without config reloading?

---

<div class="post-metadata">

**Author:** ![per.fagrell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/per.fagrell/32/33596_2.png) [@per.fagrell](https://discuss.elastic.co/u/per.fagrell)\
**Post date:** [July 23, 2018, 11:03am UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/3 "2018-07-23T11:03:08Z")

</div>

The filebeat config is this:

> filebeat.config.modules:  
> enabled: true  
> path: /etc/filebeat/modules.d/\*.yml  
> filebeat.modules:
> 
> - module: nginx  
> access:  
> enabled: true  
> error:  
> enabled: true
> - module: system  
> syslog:  
> enabled: true  
> auth:  
> enabled: true
> - module: passion  
> api:  
> enabled: true  
> filebeat.inputs:
> - type: log  
> enabled: true  
> paths:
> - /var/log/\*.log  
> setup.kibana:  
> host: kibana  
> protocol: "http"  
> output.elasticsearch:  
> hosts: ["elasticsearch"]  
> protocol: "http"  
> path: "/"

and the directory structure of my module is this:  
./\_meta  
./\_meta/config.yml  
./\_meta/docs.asciidoc  
./\_meta/fields.yml  
./\_meta/kibana  
./\_meta/kibana/6  
./api  
./api/\_meta  
./api/\_meta/fields.yml  
./api/config  
./api/config/api.yml  
./api/ingest  
./api/ingest/pipeline.json  
./api/manifest.yml  
./api/test  
./module.yml

This happens even with config reload off. Also wondering if "Enabled modules/filesets: nginx (access, error), system (auth, syslog), passion (api), ()" \<-- that empty paren set at the end might be a bad thing?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [July 23, 2018, 3:15pm UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/4 "2018-07-23T15:15:26Z")

</div>

Could you please format the config using `</>`?

---

<div class="post-metadata">

**Author:** ![per.fagrell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/per.fagrell/32/33596_2.png) [@per.fagrell](https://discuss.elastic.co/u/per.fagrell)\
**Post date:** [July 23, 2018, 6:23pm UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/5 "2018-07-23T18:23:26Z")

</div>

Right, sorry.

```
   filebeat.config.modules:
      enabled: true
      path: /etc/filebeat/modules.d/*.yml
    filebeat.modules:
    - module: nginx
      access:
        enabled: true
      error:
        enabled: true
    - module: system
      syslog:
        enabled: true
      auth:
        enabled: true
    - module: passion
      api:
        enabled: true
    filebeat.inputs:
    - type: log
      enabled: true
      paths:
        - /var/log/*.log
    setup.kibana:
      host: kibana
      protocol: "http"
    output.elasticsearch:
      hosts: ["elasticsearch"]
      protocol: "http"
      path: "/"
```

---

<div class="post-metadata">

**Author:** ![per.fagrell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/per.fagrell/32/33596_2.png) [@per.fagrell](https://discuss.elastic.co/u/per.fagrell)\
**Post date:** [July 24, 2018, 7:20pm UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/6 "2018-07-24T19:20:26Z")

</div>

Any ideas?

---

<div class="post-metadata">

**Author:** ![per.fagrell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/per.fagrell/32/33596_2.png) [@per.fagrell](https://discuss.elastic.co/u/per.fagrell)\
**Post date:** [July 24, 2018, 8:32pm UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/7 "2018-07-24T20:32:20Z")

</div>

Ok, it was my own fault. I had at some point copied a raw version of passion.yml.disabled with `{{ module }}` in it instead of `passion`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2018, 8:32pm UTC](https://discuss.elastic.co/t/cant-figure-out-source-of-config-error-in-new-filebeat-module/141102/8 "2018-08-21T20:32:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
