# Filebeat config error: YAML config parsing failed

**URL:** <https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 21, 2016, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519 "2016-06-21T14:46:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dal](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@dal](https://discuss.elastic.co/u/dal)\
**Post date:** [June 21, 2016, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/1 "2016-06-21T14:46:24Z")

</div>

Below is my filebeat configuration file. I am trying to test my config file. The only changes I made were adding the paths to the log, commenting out elastic search output and outputting to logstash. The `...` represents the commented out lines I deleted in order to format this post.

```
################### Filebeat Configuration Example #########################

############################# Filebeat ######################################
filebeat:
  # List of prospectors to fetch data.
  prospectors:
    ...
      paths:
        - /u01/app/oracle/admin/oam_domain/aserver/oam_domain/servers/AdminServer/logs/AdminServer.log
        - /u01/app/oracle/admin/oam_domain/aserver/oam_domain/servers/AdminServer/logs/AdminServer-diagnostic.log
        ...
  registry_file: /var/lib/filebeat/registry

###############################################################################
############################# Libbeat Config ##################################
# Base config file used by all other beats for using libbeat features

############################# Output ##########################################

# Configure what outputs to use when sending the data collected by the beat.
# Multiple outputs may be used.
output:

  ### Elasticsearch as output
  #elasticsearch:
    # Array of hosts to connect to.
    ...

    template:

      # Path to template file
      path: "filebeat.template.json"

      # Overwrite existing template
      #overwrite: false

    # Optional HTTP Path
    #path: "/elasticsearch"

  ### Logstash as output
  logstash:
    # The Logstash hosts
    # hosts: ["localhost:5044"]
    hosts: 
      - my.hostname:5044

    # Number of workers per Logstash host.
    #worker: 1

    # Set gzip compression level.
    #compression_level: 3

  #level: error

```

I get the following error:

```
Loading config file error: YAML config parsing failed on /usr/bin/filebeat.yml: yaml: line 278: did not find expected key. Exiting.

```

Line 278 is the `logstash:` line. I know this error is caused by indentation errors but I've parsed through my whole file and I don't see where the indentation is off.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 21, 2016, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/2 "2016-06-21T14:51:47Z")

</div>

Since you've obfuscated the file contents it's hard to help, but it looks suspicious that the "elasticsearch" line is commented but the "template" and "path" lines shortly thereafter aren't commented.

---

<div class="post-metadata">

**Author:** ![dal](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@dal](https://discuss.elastic.co/u/dal)\
**Post date:** [June 21, 2016, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/3 "2016-06-21T14:54:15Z")

</div>

it is uncommented. for logstash output i don't need to define a template?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 21, 2016, 4:36pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/4 "2016-06-21T16:36:58Z")

</div>

> for logstash output i don't need to define a template?

You _can't_ define a template for the Logstash output.

> **[Configure the Logstash output | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#_logstash_output_options)**

---

<div class="post-metadata">

**Author:** ![dal](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@dal](https://discuss.elastic.co/u/dal)\
**Post date:** [June 21, 2016, 4:39pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/5 "2016-06-21T16:39:00Z")

</div>

got it. last question: when i start filebeat with `/etc/init.d/filebeat start` should I expect to see any output other than `Starting filebeat:`? Like with Kibana or Elasticsearch you have a "running" output but with filebeats when i started it this is all i saw.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 21, 2016, 5:28pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/6 "2016-06-21T17:28:30Z")

</div>

> should I expect to see any output other than `Starting filebeat:`?

In the terminal from which you ran the init script? Probably not. If Filebeat is running it's running.

---

<div class="post-metadata">

**Author:** ![dal](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@dal](https://discuss.elastic.co/u/dal)\
**Post date:** [June 21, 2016, 5:29pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/7 "2016-06-21T17:29:27Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2016, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-config-error-yaml-config-parsing-failed/53519/8 "2016-07-12T14:47:02Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
