# Exiting: Error reading config file: required 'object', but found 'string' in field 'filebeat.inputs.0' (source:'filebeat.yml')

**URL:** <https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940>\
**Category:** Elastic Training\
**Created:** [July 8, 2023, 1:51pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940 "2023-07-08T13:51:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhakti\_Bhabal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhakti_bhabal/32/123221_2.png) [@Bhakti\_Bhabal](https://discuss.elastic.co/u/Bhakti_Bhabal)\
**Post date:** [July 8, 2023, 1:51pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/1 "2023-07-08T13:51:58Z")

</div>

HI Guys i have created the below sample filebeat.yml and verified through yamalint still i am getting the same error . I am trying to setup filebeat to work with elastic and the filebeat itself wont start up giving the error .

My config file is

```auto
###################### Filebeat Configuration Example #########################

# This file is an example configuration file highlighting only the most common
# options. The filebeat.reference.yml file from the same directory contains all the
# supported options with more comments. You can use it as a reference.
#
# You can find the full configuration reference here:
# https://www.elastic.co/guide/en/beats/filebeat/index.html

# For more available modules and options, please see the filebeat.reference.yml sample
# configuration file.

# ============================== Filebeat inputs ===============================

filebeat.inputs:
  - type:log document_type:Elasticlogs enabled:true paths:-
    D:\Elastic\elasticsearch-8.8.2-windows-x86_64\elasticsearch-8.8.2\logs
# ============================== Filebeat modules ==============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: D:\Elastic\filebeat-8.8.2-windows-x86_64\filebeat-8.8.2-windows-x86_64\modules.d\*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

# ======================= Elasticsearch template setting =======================

setup.template.settings:
  index.number_of_shards: 1
  #index.codec: best_compression
  #_source.enabled: false

# ================================== General ===================================

# The name of the shipper that publishes the network data. It can be used to group
# all the transactions sent by a single shipper in the web interface.
#name:

# The tags of the shipper are included in their own field with each
# transaction published.
#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the
# output.
#fields:
# env: staging

```

Please help me

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 8, 2023, 2:50pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/2 "2023-07-08T14:50:36Z")

</div>

Hi @Bhakti_Bhabal welcome to the community.

I formatted your code for you please.do this in the future otherwise we can not help with syntax errors.

You can format your code with 3 Backticks ``` the line before and after the code or select the code and pressing the `</>` if you click the pencil edit icon on your first post you will see what I did.

What version are you using

> [@Bhakti\_Bhabal](#):
>
> ```auto
> filebeat.inputs:
> - type:log document_type:Elasticlogs enabled:true paths:-
> D:\Elastic\elasticsearch-8.8.2-windows-x86_64\elasticsearch-8.8.2\logs
> 
> ```

This looks malformed

---

<div class="post-metadata">

**Author:** ![Bhakti\_Bhabal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhakti_bhabal/32/123221_2.png) [@Bhakti\_Bhabal](https://discuss.elastic.co/u/Bhakti_Bhabal)\
**Post date:** [July 8, 2023, 6:09pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/3 "2023-07-08T18:09:16Z")

</div>

> [@Bhakti\_Bhabal](#):
>
> ```auto
> filebeat.inputs:
> - type:log document_type:Elasticlogs enabled:true paths:-
> D:\Elastic\elasticsearch-8.8.2-windows-x86_64\elasticsearch-8.8.2\logs
> 
> ```

i am using filebeat8.8.2

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 8, 2023, 9:26pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/4 "2023-07-08T21:26:37Z")

</div>

Thanks... that code is still malformed.  
A couple Things you should use the [filestream](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-filestream.html) input as the log input is deprecated  
2nd there is no `document_type` setting  
3rd there are many syntax issue perhaps they are all cut-n-past

```auto
filebeat.inputs:
  - type:log <!--- No Space after :
    document_type:Elasticlogs <!---- Not Valid, no space after :
    enabled:true<!--- No Space after :
    paths: 
      - D:\Elastic\elasticsearch-8.8.2-windows-x86_64\elasticsearch-8.8.2\logs

```

Should look something like this follow the example from the docs

```auto
filebeat.inputs:
  - type: filestream 
    id: my-filestream-id
    enabled: true
    paths: 
      - D:\Elastic\elasticsearch-8.8.2-windows-x86_64\elasticsearch-8.8.2\logs

```

---

<div class="post-metadata">

**Author:** ![Bhakti\_Bhabal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhakti_bhabal/32/123221_2.png) [@Bhakti\_Bhabal](https://discuss.elastic.co/u/Bhakti_Bhabal)\
**Post date:** [July 12, 2023, 1:54pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/5 "2023-07-12T13:54:17Z")

</div>

Thanks a lot Stephen it worked , i have one question , when i insert data into Elastic kibana takes the timestamp of logs inserted but not the actual timings mentioned in logs . How can i get the timestamp printed in message and created a data view

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 12, 2023, 2:07pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/6 "2023-07-12T14:07:37Z")

</div>

You will need to create an ingest pipeline, parse your message etc and then set that as the timestamp that is the common flow.

Open a new topic with a sample with your log, the type / source of the log and ask for help parsing your log and setting the timestamp

If it is a common type there may be a built-in module / parser

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2023, 2:08pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940/7 "2023-08-11T14:08:21Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
