# Error loading config file: yaml: line 38: did not find expected key

**URL:** <https://discuss.elastic.co/t/error-loading-config-file-yaml-line-38-did-not-find-expected-key/240794>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [July 11, 2020, 11:11am UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-38-did-not-find-expected-key/240794 "2020-07-11T11:11:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![asagnam](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@asagnam](https://discuss.elastic.co/u/asagnam)\
**Post date:** [July 11, 2020, 11:11am UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-38-did-not-find-expected-key/240794/1 "2020-07-11T11:11:57Z")

</div>

when i was testing the winloagbeat config i got error in line 38 couldn't find expected key  
this is my winlogbeat.yml file  
kindly help me please to solve this problem  
thank you

###################### Winlogbeat Configuration Example ########################

#This file is an example configuration file highlighting only the most common

# options. The winlogbeat.reference.yml file from the same directory contains

# all the supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [https://www.elastic.co/guide/en/beats/winlogbeat/index.html](https://www.elastic.co/guide/en/beats/winlogbeat/index.html)

# ======================== Winlogbeat specific options =========================

# event\_logs specifies a list of event logs to monitor as well as any

# accompanying options. The YAML data type of event\_logs is a list of

# dictionaries.

# 

# The supported keys are name (required), tags, fields, fields\_under\_root,

# forwarded, ignore\_older, level, event\_id, provider, and include\_xml. Please

# visit the documentation for the complete details of each option.

# [https://go.es.io/WinlogbeatConfig](https://go.es.io/WinlogbeatConfig)

winlogbeat.event\_logs:

- name: Application

ignore\_older: 72h

- name: System

- name: Security

lang: javascript

```
 id: security

```

file: ${path.home}/module/security/config/winlogbeat-security.js

- name: Microsoft-Windows-Sysmon/Operational

processors:

- script:

lang: javascript

```
id: sysmon

```

file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

- name: ForwardedEvents

tags: [forwarded]

#processors:

# - script:

```
      when.equals.winlog.channel: Security

```

#lang: javascript

```
 #id: security

```

#file: ${path.home}/module/security/config/winlogbeat-security.js

- script:

when.equals.winlog.channel: Microsoft-Windows-Sysmon/Operational

lang: javascript

```
id: sysmon
      file: ${path.home}/module/sysmon/config/winlogbeat-sysmon.js

```

# ====================== Elasticsearch template settings =======================

setup.template.settings:

index.number\_of\_shards: 1

#index.codec: best\_compression

#\_source.enabled: false

# ================================== General ===================================

# The name of the shipper that publishes the network data. It can be used to group

# all the transactions sent by a single shipper in the web interface.

#name:

# The tags of the shipper are included in their own field with each

# transaction published.

#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the

# output.

#fields:

# env: staging

# ================================= Dashboards =================================

# These settings control loading the sample dashboards to the Kibana index. Loading

# the dashboards is disabled by default and can be enabled either by setting the

# options here or by using the `setup` command.

setup.dashboards.enabled: true

# The URL from where to download the dashboards archive. By default this URL

# has a value which is computed based on the Beat name and version. For released

# versions, this URL points to the dashboard archive on the [artifacts.elastic.co](http://artifacts.elastic.co)

# website.

#setup.dashboards.url:

# =================================== Kibana ===================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.

# This requires a Kibana endpoint configuration.

setup.kibana:

# Kibana Host

# Scheme and port can be left out and will be set to the default (http and 5601)

# In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)

# IPv6 addresses should always be defined as: https://[2001:db8::1]:5601

host: "192.168.3.7:5601"

# Kibana Space ID

# ID of the Kibana Space into which the dashboards should be loaded. By default,

# the Default Space will be used.

#space.id:

# =============================== Elastic Cloud ================================

# These settings simplify using Winlogbeat with the Elastic Cloud ([https://cloud.elastic.co/](https://cloud.elastic.co/)).

# The cloud.id setting overwrites the `output.elasticsearch.hosts` and

# `setup.kibana.host` options.

# You can find the `cloud.id` in the Elastic Cloud web UI.

#cloud.id:

# The cloud.auth setting overwrites the `output.elasticsearch.username` and

# `output.elasticsearch.password` settings. The format is `<user>:<pass>`.

#cloud.auth:

# ================================== Outputs ===================================

# Configure what output to use when sending the data collected by the beat.

# ---------------------------- Elasticsearch Output ----------------------------

output.elasticsearch:

# Array of hosts to connect to.

hosts: ["192.168.3.7:9200"]

# Protocol - either `http` (default) or `https`.

#protocol: "https"

# Authentication credentials - either API key or username/password.

#api\_key: "id:api\_key"

#username: "elastic"

#password: "changeme"

# ------------------------------ Logstash Output -------------------------------

#output.logstash:

# The Logstash hosts

#hosts: ["localhost:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

# ================================= Processors =================================

processors:

- add\_host\_metadata:  
when.not.contains.tags: forwarded
- add\_cloud\_metadata: ~

# ================================== Logging ===================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

#logging.selectors: ["\*"]

# ============================= X-Pack Monitoring ==============================

# Winlogbeat can export internal metrics to a central Elasticsearch monitoring

# cluster. This requires xpack monitoring to be enabled in Elasticsearch. The

# reporting is disabled by default.

# Set to true to enable the monitoring reporter.

#monitoring.enabled: false

# Sets the UUID of the Elasticsearch cluster under which monitoring data for this

# Winlogbeat instance will appear in the Stack Monitoring UI. If output.elasticsearch

# is enabled, the UUID is derived from the Elasticsearch cluster referenced by output.elasticsearch.

#monitoring.cluster\_uuid:

# Uncomment to send the metrics to Elasticsearch. Most settings from the

# Elasticsearch output are accepted here as well.

# Note that the settings should point to your Elasticsearch _monitoring_ cluster.

# Any setting that is not set is automatically inherited from the Elasticsearch

# output configuration, so if you have the Elasticsearch output configured such

# that it is pointing to your Elasticsearch monitoring cluster, you can simply

# uncomment the following line.

#monitoring.elasticsearch:

# ================================= Migration ==================================

# This allows to enable 6.7 migration aliases

#migration.6\_to\_7.enabled: true

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2020, 1:11pm UTC](https://discuss.elastic.co/t/error-loading-config-file-yaml-line-38-did-not-find-expected-key/240794/2 "2020-08-08T13:11:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
