# Filebeat beta1 not working for my prospectors .yml file that was working on alpha 5

**URL:** <https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 29, 2016, 4:47pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832 "2016-09-29T16:47:02Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![agonzalez](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Post date:** [September 29, 2016, 4:47pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/1 "2016-09-29T16:47:03Z")

</div>

I have a large prospector list that was working fine on 5.0-alpha5.

If i upgrade filebeat to beta1 no logs are seen in kibana. I dont see any error on /var/log. If i downgrade to alpha5 logs can be seen on kibana again.

I cant paste all file here cause there is a limit.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [September 29, 2016, 6:34pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/2 "2016-09-29T18:34:21Z")

</div>

can you share some filebeat logs + config? Did you use logstash output with tls?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 3, 2016, 8:22am UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/3 "2016-10-03T08:22:12Z")

</div>

@agonzalez You can share the logs and configs as a gist and only share the links here.

---

<div class="post-metadata">

**Author:** ![agonzalez](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Post date:** [October 3, 2016, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/4 "2016-10-03T14:47:27Z")

</div>

I found the problem, it was a blank line between one of the 41 paths/prospectors, look like alpha5 worked fine with that and beta1 no. I removed the blank line and service started to work fine.

thanks!

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 3, 2016, 3:38pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/5 "2016-10-03T15:38:55Z")

</div>

@agonzalez Interesting. Could you share the two different options you are talking about? Would be interesting to test if we broke here some BC.

Is that what you are referring to?

Before

```auto
filebeat.prospectors:
- paths:
  - test.log

  - test2.log

```

After

```auto
filebeat.prospectors:
- paths:
  - test.log
  - test2.log

```

---

<div class="post-metadata">

**Author:** ![agonzalez](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Post date:** [October 3, 2016, 3:43pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/6 "2016-10-03T15:43:50Z")

</div>

No, I have 41 differents paths/document\_types. It was something like:

```
-
  paths:
    - /usr/logs.dir/log1-*.log
  document_type: log1
  exclude_lines: ["^$"]
  fields:
   asset_tag: ${ASSET_TAG}

-
  paths:
    - /usr/logs.dir/log2-*.log
  document_type: log2
  exclude_lines: ["^$"]
  fields:
   asset_tag: ${ASSET_TAG}
```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 3, 2016, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/7 "2016-10-03T15:46:31Z")

</div>

Ok, and you removed the newline before the second `-` prospector and it worked again?

---

<div class="post-metadata">

**Author:** ![agonzalez](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Post date:** [October 3, 2016, 3:48pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/8 "2016-10-03T15:48:28Z")

</div>

yes, that is what i did and fixed the issue. Before that I tried to "strings" the file in case there were some bad character also but until i realize there was a blank line and removed it didnt work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2016, 4:47pm UTC](https://discuss.elastic.co/t/filebeat-beta1-not-working-for-my-prospectors-yml-file-that-was-working-on-alpha-5/61832/9 "2016-10-20T16:47:03Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
