# Filebeat failing to start due to YAML error, but which config file is it complaining about?

**URL:** <https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047>\
**Category:** Elasticsearch\
**Created:** [August 17, 2023, 6:21pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047 "2023-08-17T18:21:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 17, 2023, 6:21pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/1 "2023-08-17T18:21:39Z")

</div>

I'm attempting to use Filebeat to ingest logs from Zeek, but I'm getting the following error when I start Filebeat:

> <https://gist.github.com/packetuser/69473877186cd7e0b0ac78b430a15063>

Here's my /etc/filebeat/filebeat.yml file:

> <https://gist.github.com/packetuser/69473877186cd7e0b0ac78b430a15063>

Yamllint tells me that there's an issue with this: "Map keys must be unique at line 234, column 1" (that line is 'output.elasticsearch:'). I don't understand!

And here's my /etc/filebeat/modules.d/zeek.yml file:

> <https://gist.github.com/packetuser/d5832ab282013291d495ccfce1154046>

Yamllint tells me this one is formatted correctly.

The error message doesn't tell me which file is problematic.

Any assistance would be greatly appreciated!

Also, what am I doing wrong with my Gist links? Other people have sleek little windows with just the text content. I've got these chunky things with lots of Github stuff in the frame.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 17, 2023, 7:14pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/2 "2023-08-17T19:14:37Z")

</div>

> [@artschooldropout](#):
>
> The error message doesn't tell me which file is problematic.

What is the error message? You didn't share it.

Looking at your `filebeat.yml` file it has a duplicated key, you have `output.elasticsearch` and `hosts` twice in the configuration, you can have it only once.

Check lines `139`-`141` and lines `234`-`240`.

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 17, 2023, 7:28pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/3 "2023-08-17T19:28:57Z")

</div>

Whoops, my mistake. The error is here:

> <https://gist.github.com/packetuser/677d6d6e95b4b61fe3178346f98e4f1a>

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 17, 2023, 7:48pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/4 "2023-08-17T19:48:14Z")

</div>

Ok, I commented out the duplicate key, and restarted the elasticsearch and filebeat services. I get the same error from filebeat.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 17, 2023, 7:51pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/5 "2023-08-17T19:51:29Z")

</div>

This is the entire log you have? Do you have other lines? This is not helpful indeed.

Please share the entire log you are receiving from filebeat.

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 17, 2023, 8:08pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/6 "2023-08-17T20:08:10Z")

</div>

Yes, here's the whole error:

> <https://gist.github.com/packetuser/311b5c608a962a988813a59d13f342f6>

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 17, 2023, 8:22pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/7 "2023-08-17T20:22:23Z")

</div>

> [@artschooldropout](#):
>
> [/etc/filebeat/modules.d/zeek.yml · GitHub](https://gist.github.com/packetuser/d5832ab282013291d495ccfce1154046)

The error is in the `zeek.yml` file.

> {"log.level":"error","@timestamp":"2023-08-17T19:47:42.203Z","log.origin":{"file.name":"cfgfile/reload.go","file.line":270},"message":"Error loading config from file ' **/etc/filebeat/modules.d/zeek.yml**', error invalid config: yaml: line 5: mapping values are not allowed in this context","service.name":"filebeat","ecs.version":"1.6.0"}

Looking at the file you shared:

```auto
- module: zeek
    capture_loss:
        enabled: true
        var.paths: ["/mnt/Bro/current/capture_loss.log"]
    connection:
        enabled: true
        var.paths: ["/mnt/Bro/current/conn.log"]

```

The indentation is different from the one that is [expected](https://github.com/elastic/beats/blob/main/x-pack/filebeat/module/zeek/_meta/config.yml).

`capture_loss`, `connection` etc should be on the same column of `- module`.

```auto

- module: zeek
  capture_loss:
    enabled: true
    var.paths: ["/mnt/Bro/current/capture_loss.log"]
  connection:
    enabled: true
    var.paths: ["/mnt/Bro/current/conn.log"]

```

Not sure if this is the issue, but since yml files are pretty sensible to indentation, it may be.

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [August 17, 2023, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/8 "2023-08-17T20:48:47Z")

</div>

Yes! This was the issue! Thank you so much for your help.

I had copied and pasted the config file to notepad++, which messed with the indentation.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2023, 8:49pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047/9 "2023-09-14T20:49:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
