Configuring filebeat.yml


I'm following instructions on the documentation provided on this site to configure filebeat.yml file.

- type: log
    - /path/to/file/logstash-tutorial.log 
  hosts: ["localhost:5044"]

then when I run the command filebeat -e -c filebeat.yml -d "publish" I get the following error

C:\Program Files\Filebeat>filebeat -e -c filebeat.yml -d "publish"
Exiting: error loading config file: yaml: line 66: did not find expected key

This is the configuration file


# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

- type: log
- C:\Users\testuser\Downloads\logstash-tutorial.log

# Change to true to enable this input configuration.
enabled: true
# Paths that should be crawled and fetched. Glob based paths.
    - /var/log/*.log
    #- c:\programdata\elasticsearch\logs\*

  # Exclude lines. A list of regular expressions to match. It drops the lines that are
  # matching any regular expression from the list.
  #exclude_lines: ['^DBG']

  # Include lines. A list of regular expressions to match. It exports the lines that are
  # matching any regular expression from the list.
  #include_lines: ['^ERR', '^WARN']

  # Exclude files. A list of regular expressions to match. Filebeat drops the files that
  # are matching any regular expression from the list. By default, no files are dropped.
  #exclude_files: ['.gz$']

  # Optional additional fields. These fields can be freely picked
  # to add additional information to the crawled log files for filtering
  #  level: debug
  #  review: 1

  ### Multiline options

  # Multiline can be used for log messages spanning multiple lines. This is common
  # for Java Stack Traces or C-Line Continuation

  # The regexp Pattern that has to be matched. The example pattern matches all lines starting with [
  #multiline.pattern: ^\[

  # Defines if the pattern set under pattern should be negated or not. Default is false.
  #multiline.negate: false

  # Match can be set to "after" or "before". It is used to define if lines should be append to a pattern
  # that was (not) matched before or after or as long as a pattern is not matched based on negate.
  # Note: After is the equivalent to previous and before is the equivalent to to next in Logstash
  #multiline.match: after

# filestream is an experimental input. It is going to replace log input in the future.
- type: filestream

  # Change to true to enable this input configuration.
  enabled: false

  # Paths that should be crawled and fetched. Glob based paths.
    - /var/log/*.log
    #- c:\programdata\elasticsearch\logs\*

  # Exclude lines. A list of regular expressions to match. It drops the lines that are
  # matching any regular expression from the list.
  #exclude_lines: ['^DBG']

  # Include lines. A list of regular expressions to match. It exports the lines that are
  # matching any regular expression from the list.
  #include_lines: ['^ERR', '^WARN']

  # Exclude files. A list of regular expressions to match. Filebeat drops the files that
  # are matching any regular expression from the list. By default, no files are dropped.
  #prospector.scanner.exclude_files: ['.gz$']

  # Optional additional fields. These fields can be freely picked
  # to add additional information to the crawled log files for filtering
  #  level: debug
  #  review: 1

I did try to use port 9600 for logstash, I also used 5044 because that is what's in the example.

This is a filebeat question, so you should ask in the filebeat forum, not the logstash forum. You can edit the question and move it.

That said, yaml is very picky about indentation. It matters a lot, and my guess would be that your indentation is wrong.

1 Like

Besides the indentation issue mentioned above, in the filebeat.yml that u show, the file input has 2 paths keys. The example one should be removed or commented out.


thank you, I commented out the last two paths as well as found out the indentation issue.
However now, I get a message that no output is defined.
However I do have an output defined.

# ------------------------------ Logstash Output -------------------------------
  # The Logstash hosts
  hosts: ["localhost:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

or should the output be under the filebeat.inputs as it's shown in the example?

If so, why is it there instead of being under its own output section?

thank you, I apologize it, I have changed the question from logstash to beats.

Would you mind sharing the filebeat version and debug messages you're getting?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.