# Filebeat is not starting

**URL:** <https://discuss.elastic.co/t/filebeat-is-not-starting/57832>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 11, 2016, 3:28pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832 "2016-08-11T15:28:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rai](https://avatars.discourse-cdn.com/v4/letter/r/67e7ee/32.png) [@rai](https://discuss.elastic.co/u/rai)\
**Post date:** [August 11, 2016, 3:28pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/1 "2016-08-11T15:28:02Z")

</div>

I am new to ELK stack and trying make it work. First I tried to configure filebeat to display syslog on Kibana and able to get through but when I tried to get DOCS logs, Filebeat failed to start.

Following is snippet of filebeat.yml file

# - /var/log/secure

# - /var/log/messages

```
      - /var/lib/mesos/slave/slaves/*/frameworks/*/executors/*/runs/latest/stdout

```

input\_type: log  
document\_type: syslog  
I am staring filebeat using following command on Linux box.  
service filebeat start -v -d "\*"  
I really need you guys to help me out as I am really dead time line for this project. One more thing, where I can see filebeat log?

---

<div class="post-metadata">

**Author:** ![rai](https://avatars.discourse-cdn.com/v4/letter/r/67e7ee/32.png) [@rai](https://discuss.elastic.co/u/rai)\
**Post date:** [August 11, 2016, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/2 "2016-08-11T16:31:14Z")

</div>

I am getting following error of consol

[bin]# ./filebeat -e -c /etc/filebeat/filebeat.yml -v -d "\*"  
Loading config file error: YAML config parsing failed on /etc/filebeat/filebeat.yml: yaml: line 73: did not find expected key. Exiting.

and on line 73, I have document\_type: syslog

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 11, 2016, 4:34pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/3 "2016-08-11T16:34:38Z")

</div>

> service filebeat start -v -d "\*"

The service command doesn't take arguments like above. How you configure the startup arguments depends on things like whether your OS uses systemd, whether you have an init script, what it looks like, etc.

> One more thing, where I can see filebeat log?

See [Configure logging | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-logging.html).

> Loading config file error: YAML config parsing failed on /etc/filebeat/filebeat.yml: yaml: line 73: did not find expected key. Exiting.

Impossible to tell what's wrong without seeing the whole file. **When you post it, make sure you format it as code with the `</>` button.**

---

<div class="post-metadata">

**Author:** ![rai](https://avatars.discourse-cdn.com/v4/letter/r/67e7ee/32.png) [@rai](https://discuss.elastic.co/u/rai)\
**Post date:** [August 11, 2016, 5:06pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/4 "2016-08-11T17:06:41Z")

</div>

Thank you so much for your reply.  
After removing the document\_type = syslog `indent preformatted text by 4 spaces`from filebeat.yml , it started without error `indent preformatted text by 4 spaces`and able to see the log on Kibana. But I don't understand why it's causing this issue as I have the filter configuration corresponding to syslog on my logstash file which is as follow  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
`indent preformatted text by 4 spaces`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 11, 2016, 5:34pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/5 "2016-08-11T17:34:10Z")

</div>

As I said: Impossible to tell what's wrong without seeing the whole file.

---

<div class="post-metadata">

**Author:** ![rai](https://avatars.discourse-cdn.com/v4/letter/r/67e7ee/32.png) [@rai](https://discuss.elastic.co/u/rai)\
**Post date:** [August 11, 2016, 11:48pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/6 "2016-08-11T23:48:47Z")

</div>

Thanks again.actually it was formatting issue in filebeat.yml [file.It](http://file.It)'s working now,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2016, 3:28pm UTC](https://discuss.elastic.co/t/filebeat-is-not-starting/57832/7 "2016-09-01T15:28:43Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
