# Filebeat Log Error

**URL:** <https://discuss.elastic.co/t/filebeat-log-error/146217>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 27, 2018, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217 "2018-08-27T17:49:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![robegome](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@robegome](https://discuss.elastic.co/u/robegome)\
**Post date:** [August 27, 2018, 5:49pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/1 "2018-08-27T17:49:16Z")

</div>

Hello everyone!

I have an error with Filebeat... checking /var/log/filebeat/filebeat , I am seeing this error:

> _2018-08-27T17:37:09.165Z INFO instance/beat.go:273 Setup Beat: **filebeat; Version: 6.4.0** _  
> _2018-08-27T17:37:09.167Z INFO pipeline/module.go:98 Beat name: [elk640.oracle.com](http://elk640.oracle.com)_  
> _2018-08-27T17:37:09.168Z INFO [monitoring] log/log.go:114 Starting metrics logging every 30s_  
> _2018-08-27T17:37:09.168Z INFO instance/beat.go:367 filebeat start running._  
> _2018-08-27T17:37:09.168Z INFO registrar/registrar.go:134 Loading registrar data from /var/lib/filebeat/registry_  
> _2018-08-27T17:37:09.169Z INFO registrar/registrar.go:141 States Loaded from registrar: 10_  
> _2018-08-27T17:37:09.169Z WARN beater/filebeat.go:371 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning._  
> _2018-08-27T17:37:09.169Z INFO crawler/crawler.go:72 Loading Inputs: 1_  
> _2018-08-27T17:37:09.169Z INFO log/input.go:138 Configured paths: [/var/log/\*.log]_  
> _2018-08-27T17:37:09.169Z INFO input/input.go:114 Starting input of type: log; ID: 11204088409762598069_  
> _2018-08-27T17:37:09.170Z INFO crawler/crawler.go:106 Loading and starting Inputs completed. Enabled inputs: 1_  
> _2018-08-27T17:37:09.170Z INFO cfgfile/reload.go:140 Config reloader started_  
> _2018-08-27T17:37:19.170Z \*\*ERROR cfgfile/reload.go:213 Error loading config: invalid config: yaml: line 9: could not find expected ':'_\*\*  
> _2018-08-27T17:37:19.173Z INFO log/input.go:138 Configured paths: [/var/log/auth.log\* /var/log/secure\*]_  
> _2018-08-27T17:37:19.174Z INFO log/input.go:138 Configured paths: [/var/log/messages\* /var/log/syslog\*]_  
> _2018-08-27T17:37:19.174Z INFO input/input.go:114 Starting input of type: log; ID: 300630154341581075_  
> _2018-08-27T17:37:19.174Z INFO input/input.go:114 Starting input of type: log; ID: 17766284131079967355_  
> _2018-08-27T17:37:19.176Z INFO log/harvester.go:251 Harvester started for file: /var/log/messages_  
> _2018-08-27T17:37:29.174Z \*\*ERROR cfgfile/reload.go:213 Error loading config: invalid config: yaml: line 9: could not find expected ':'_\*\*  
> _2018-08-27T17:37:39.171Z INFO [monitoring] log/log.go:141 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":10,"time":{"ms":17}},"total":{"ticks":40,"time":{"ms":47},"value":40},"user":{"ticks":30,"time":{"ms":30}}},"info":{"ephemeral\_id":"21688425-e712-4fcb-99f4-98dcd570a709","uptime":{"ms":30022}},"memstats":{"gc\_next":6460672,"memory\_alloc":4861120,"memory\_total":7688776,"rss":23183360}},"filebeat":{"events":{"added":14,"done":14},"harvester":{"open\_files":1,"running":1,"started":1}},"libbeat":{"config":{"module":{"running":0},"reloads":2},"output":{"events":{"acked":5,"batches":2,"total":5},"read":{"bytes":12},"type":"logstash","write":{"bytes":1233}},"pipeline":{"clients":3,"events":{"active":0,"filtered":9,"published":5,"retry":4,"total":14},"queue":{"acked":5}}},"registrar":{"states":{"current":10,"update":14},"writes":{"success":11,"total":11}},"system":{"cpu":{"cores":2},"load":{"1":0.99,"15":0.51,"5":0.84,"norm":{"1":0.495,"15":0.255,"5":0.42}}}}}}_  
> **\> _2018-08-27T17:37:39.175Z ERROR cfgfile/reload.go:213 Error loading config: invalid config: yaml: line 9: could not find expected ':'_**  
> **\> _2018-08-27T17:37:49.176Z ERROR cfgfile/reload.go:213 Error loading config: invalid config: yaml: line 9: could not find expected ':'_**  
> **\> _2018-08-27T17:37:59.177Z ERROR cfgfile/reload.go:213 Error loading config: invalid config: yaml: line 9: could not find expected ':'_**  
> _2018-08-27T17:38:09.170Z INFO [monitoring] log/log.go:141 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":20,"time":{"ms":12}},"total":{"ticks":90,"time":{"ms":57},"value":90},"user":{"ticks":70,"time":{"ms":45}}},"info":{"ephemeral\_id":"21688425-e712-4fcb-99f4-98dcd570a709","uptime":{"ms":60022}},"memstats":{"gc\_next":6532256,"memory\_alloc":3277496,"memory\_total":21894736,"rss":3878912}},"filebeat":{"events":{"added":13,"done":13},"harvester":{"open\_files":1,"running":1}},"libbeat":{"config":{"module":{"running":0},"reloads":3},"output":{"events":{"acked":13,"batches":9,"total":13},"read":{"bytes":60},"write":{"bytes":4191}},"pipeline":{"clients":3,"events":{"active":0,"published":13,"total":13},"queue":{"acked":13}}},"registrar":{"states":{"current":10,"update":13},"writes":{"success":9,"total":9}},"system":{"load":{"1":0.6,"15":0.5,"5":0.76,"norm":{"1":0.3,"15":0.25,"5":0.38}}}}}}_  
> **\> _2018-08-27T17:38:09.177Z ERROR cfgfile/reload.go:213 Error loading config: invalid config: yaml: line 9: could not find expected ':'_**

I checked several time my filebeat.yml, logstash.yml, elasticsearch.yml and kibana.yml and I couldn't find any error in line 9... do you know how I could fix this error?

Thanks!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 27, 2018, 9:07pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/2 "2018-08-27T21:07:24Z")

</div>

The error is not in filebeat.yml itself. It looks like filebeat is configured with config reloading. It complains about one of the files found in the reloading-directory to be invalid yaml.

---

<div class="post-metadata">

**Author:** ![robegome](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@robegome](https://discuss.elastic.co/u/robegome)\
**Post date:** [August 27, 2018, 9:38pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/3 "2018-08-27T21:38:30Z")

</div>

that is correct, I enble the reloading config in my filebeat.yml

> #============================= Filebeat modules ===============================
> 
> filebeat.config.modules:
> 
> # Glob pattern for configuration loading
> 
> path: ${path.config}/modules.d/\*.yml
> 
> # Set to true to enable config reloading
> 
> **reload.enabled: true**
> 
> # Period on which files under path should be checked for changes
> 
> #reload.period: 10s

So, if that is not an error... I assume this thread could be closed

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 28, 2018, 2:01pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/4 "2018-08-28T14:01:09Z")

</div>

It is an error. There is an invalid configuration file in your modules.d directory. Unfortunately the error message does not report the actual file that failed ☹

I created an issue on the actual error message being not very helpful: [#8122](https://github.com/elastic/beats/issues/8122).

---

<div class="post-metadata">

**Author:** ![robegome](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@robegome](https://discuss.elastic.co/u/robegome)\
**Post date:** [August 28, 2018, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/5 "2018-08-28T14:59:28Z")

</div>

Hi Steffen, ok got it... if it is useful i am going to paste the three files (.conf) that I am using in Logstash (and beats):

**input.conf**  
_cat /etc/logstash/conf.d/input.conf_

> input {  
> beats {  
> port =\> 5044  
> }  
> }

**filter.conf**  
_cat /etc/logstash/conf.d/filter.conf_

> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> syslog\_pri { }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> }

**output.conf**  
_cat /etc/logstash/conf.d/output.conf_

> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

I hope this could help to resolve the issue... THANKS!

---

<div class="post-metadata">

**Author:** ![robegome](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@robegome](https://discuss.elastic.co/u/robegome)\
**Post date:** [August 28, 2018, 3:41pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/6 "2018-08-28T15:41:55Z")

</div>

... also I am adding the info that I have regarding my modules.d

output enable modules:

**/usr/share/filebeat/bin/filebeat --path.config=/etc/filebeat/ modules list**

```
Enabled:
    nginx
    system

Disabled:
apache2
auditd
elasticsearch
icinga
iis
kafka
kibana
logstash
mongodb
mysql
osquery
postgresql
redis
traefik

```

this is the content in **NGINX** :

_ **cat nginx.yml** _

```
- module: nginx
  # Access logs
  access:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths ["/path/to/log/nginx/access.log*"]

  # Error logs
  error:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/path/to/log/nginx/error.log*"]

```

this is the content in **SYSTEM** :

**_cat system.yml_**

```
- module: system
  # Syslog
  syslog:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

    # Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
    #var.convert_timezone: false

  # Authorization logs
  auth:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

    # Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
    #var.convert_timezone: false
```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 28, 2018, 7:42pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/7 "2018-08-28T19:42:30Z")

</div>

You can test yaml syntax in filebeat configuration files using some yaml linters. E.g. a web based linter can be found at [http://www.yamllint.com](http://www.yamllint.com).

The problem is in your nginx configuration. You are missing the `:` symbol at line 9.

Your config is:

```auto
    var.paths ["/path/to/log/nginx/access.log*"]

```

but it must be:

```auto
    var.paths: ["/path/to/log/nginx/access.log*"]

```

---

<div class="post-metadata">

**Author:** ![robegome](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@robegome](https://discuss.elastic.co/u/robegome)\
**Post date:** [August 28, 2018, 9:45pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/8 "2018-08-28T21:45:43Z")

</div>

yes, you are right... there is a typo in that line!!

I appreciate your help and now all is working better... the error about `Error loading config: invalid config: yaml: line 9: could not find expected ':'` has been gone!

THANKS!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2018, 9:45pm UTC](https://discuss.elastic.co/t/filebeat-log-error/146217/9 "2018-09-25T21:45:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
