# ERROR instance/beat Exiting: Error in initing prospector: No paths were defined for prospector accessing config

**URL:** <https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 10, 2018, 11:03pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553 "2018-04-10T23:03:29Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [April 10, 2018, 11:03pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/1 "2018-04-10T23:03:30Z")

</div>

I am trying to visualize sample data on Kibana using Windows. I followed the link to Security Analytics section to setup Elasticsearch, Kibana and Filebeats. [Link to installation (Security Analytics)](https://www.elastic.co/solutions/security-analytics)

I have installed Elastic search and Kibana, and have been able to successfully launch both. The description in the link states to configure the filebeat.yml file.

I have configured the filebeat.yml file as follows:

```
###################### Filebeat Configuration Example #########################

#=========================== Filebeat prospectors =============================

filebeat.prospectors:

- type: log

  # Change to true to enable this prospector configuration.
  enabled: false

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/log/*.log
  #- c:\programdata\elasticsearch\logs\*

#exclude_lines: ['^DBG']

#include_lines: ['^ERR', '^WARN']

#exclude_files: ['.gz$']

#fields:
# level: debug
# review: 1

### Multiline options

# The regexp Pattern that has to be matched. The example pattern matches all lines starting with [
#multiline.pattern: ^\[

# Defines if the pattern set under pattern should be negated or not. Default is false.
#multiline.negate: false

# Match can be set to "after" or "before". It is used to define if lines should be append to a pattern
# that was (not) matched before or after or as long as a pattern is not matched based on negate.

#============================= Filebeat modules ===============================

filebeat.config.modules:
# Glob pattern for configuration loading
path: ${path.config}/modules.d/*.yml

# Set to true to enable config reloading
reload.enabled: false

# Period on which files under path should be checked for changes
#reload.period: 10s

#==================== Elasticsearch template setting ==========================

setup.template.settings:
index.number_of_shards: 3
#index.codec: best_compression
#_source.enabled: false

#================================ General =====================================

# The name of the shipper that publishes the network data. It can be used to group
# all the transactions sent by a single shipper in the web interface.
#name:

# The tags of the shipper are included in their own field with each
# transaction published.
#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the
# output.
#fields:
# env: staging

#============================== Dashboards =====================================
# These settings control loading the sample dashboards to the Kibana index. Loading
# the dashboards is disabled by default and can be enabled either by setting the
# options here, or by using the `-setup` CLI flag or the `setup` command.
#setup.dashboards.enabled: false

# The URL from where to download the dashboards archive. By default this URL  
# has a value which is computed based on the Beat name and version. For released
# versions, this URL points to the dashboard archive on the artifacts.elastic.co
# website.
#setup.dashboards.url:

#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
# This requires a Kibana endpoint configuration.
setup.kibana:

# Kibana Host
# Scheme and port can be left out and will be set to the default (http and 5601)
# In case you specify and additional path, the scheme is required: http://localhost:5601/path
# IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
#host: "localhost:5601"

#============================= Elastic Cloud ==================================

# These settings simplify using filebeat with the Elastic Cloud (https://cloud.elastic.co/).

# The cloud.id setting overwrites the `output.elasticsearch.hosts` and
# `setup.kibana.host` options.
# You can find the `cloud.id` in the Elastic Cloud web UI.
#cloud.id:

# The cloud.auth setting overwrites the `output.elasticsearch.username` and
# `output.elasticsearch.password` settings. The format is `<user>:<pass>`.
#cloud.auth:

#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
# Array of hosts to connect to.
hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.
#protocol: "https"
username: "elastic"
password: "n2yHQc8Cp1K2iRrOrNcV"

#----------------------------- Logstash output --------------------------------
#output.logstash:
# The Logstash hosts
#hosts: ["localhost:5044"]

# Optional SSL. By default is off.
# List of root certificates for HTTPS server verifications
#ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication
#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key
#ssl.key: "/etc/pki/client/cert.key"

#================================ Logging =====================================

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.
# To enable all selectors use ["*"]. Examples of other selectors are "beat",
# "publish", "service".
#logging.selectors: ["*"]

#============================== Xpack Monitoring ===============================
# filebeat can export internal metrics to a central Elasticsearch monitoring
# cluster. This requires xpack monitoring to be enabled in Elasticsearch. The
# reporting is disabled by default.

# Set to true to enable the monitoring reporter.
#xpack.monitoring.enabled: false

# Uncomment to send the metrics to Elasticsearch. Most settings from the
# Elasticsearch output are accepted here as well. Any setting that is not set is
# automatically inherited from the Elasticsearch output configuration, so if you
# have the Elasticsearch output configured, you can simply uncomment the
# following line.
#xpack.monitoring.elasticsearch:

```

After running the command ".\filebeat -e -modules=system --setup", filebeat begins, successfully connecting to Elasticsearch and loading Kibana dashboards.

But when I click on the dashboard section on Kibana, the Filebeat process exits with an error message saying "Exiting: Error in initing prospector: No paths were defined for prospector accessing config".

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/0/8/08a736e45319faf63f8b2a85c9d67d57b78c4a0f.PNG)

Am I doing something wrong? How can this issue be rectified?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 11, 2018, 2:25pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/2 "2018-04-11T14:25:07Z")

</div>

```yaml
- type: log

  # Change to true to enable this prospector configuration.
  enabled: false

```

Hello @APJ , In the extract above from your configuration, you have to enable the prospector by settings the `enabled` key to true. The error mean no prospectors or module are enabled in that configuration.

> I am trying to visualize sample data on Kibana using Windows. I followed the link to Security Analytics section to setup Elasticsearch, Kibana and Filebeats. Link to installation

Which page are you referring?

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [April 11, 2018, 3:28pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/3 "2018-04-11T15:28:24Z")

</div>

I have updated my question to create a hyperlink to the page. I am following Auth logs under Security and Analytics section. I changed enabled to true. I still get the same error.

![Capture](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4ef5ed54a21cd0183f8d53cabfb382f9c5b67713.PNG)

Could you please help me resolve this issue?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 11, 2018, 3:40pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/4 "2018-04-11T15:40:49Z")

</div>

Can you add the output of `./filebeat export config`

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [April 11, 2018, 5:38pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/5 "2018-04-11T17:38:52Z")

</div>

Sure. Here is the output:

 ![Capture1](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b5dea04fb3330b64c8ea2d03fc0582d6065fc08.PNG)

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [April 11, 2018, 6:52pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/6 "2018-04-11T18:52:27Z")

</div>

Is there anything wrong with the config file? I only followed the steps on the Security Analytics section!

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 12, 2018, 1:40pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/7 "2018-04-12T13:40:00Z")

</div>

@apj Which part of the tutorial you were following? Auth Logs, Audit Events, NetFlow, DNS Traffic or Arcsight? Maybe one of them doesn't correctly work on windows?

---

<div class="post-metadata">

**Author:** ![APJ](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@APJ](https://discuss.elastic.co/u/APJ)\
**Post date:** [April 12, 2018, 5:04pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/8 "2018-04-12T17:04:47Z")

</div>

@pierhugues I am following Auth Logs! Does it work right on windows? Also, Are there any other sections that don't work well on windows?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 13, 2018, 1:24pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/9 "2018-04-13T13:24:55Z")

</div>

I've looked and the `system` module doesn't work with windows, we need to make distinction about that in that page.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 13, 2018, 1:25pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/10 "2018-04-13T13:25:57Z")

</div>

The other sections should work on windows.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2018, 1:26pm UTC](https://discuss.elastic.co/t/error-instance-beat-exiting-error-in-initing-prospector-no-paths-were-defined-for-prospector-accessing-config/127553/11 "2018-05-11T13:26:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
