# Filebeat make update fails for new custom module

**URL:** <https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 24, 2020, 8:04am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070 "2020-08-24T08:04:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cpohl](https://avatars.discourse-cdn.com/v4/letter/c/838e76/32.png) [@cpohl](https://discuss.elastic.co/u/cpohl)\
**Post date:** [August 24, 2020, 8:04am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070/1 "2020-08-24T08:04:52Z")

</div>

I have followed the instructions:  
[https://www.elastic.co/guide/en/beats/devguide/7.8/filebeat-modules-devguide.html](https://www.elastic.co/guide/en/beats/devguide/7.8/filebeat-modules-devguide.html)

create-module, create-fileset and create-fields all work correctly with no errors.  
But the make update throws the following error:

```auto
mage update
Generated fields.yml for filebeat to /srv/test/beats/filebeat/fields.yml
Generated global fields.yml file for filebeat is invalid: yaml: line 6613: found a tab character where an indentation space is expected
exit status 3
Error: running "go run -mod=readonly /srv/test/beats/libbeat/scripts/cmd/global_fields/main.go -es_beats_path /srv/test/beats -beat_path /srv/test/beats/filebeat -out fields.yml module" failed with exit code 1
Makefile:13: recipe for target 'update' failed
make: *** [update] Error 1

```

The global fields.yml has only 5.334 lines. So I don´t understand the error message "...is invalid: yaml: line 6613...".

OS is: SLES 12 SP5

Can anyone help me?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 26, 2020, 8:39pm UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070/2 "2020-08-26T20:39:03Z")

</div>

Hey @cpohl, welcome to discuss 🙂

Try checking the yaml syntax of the `fields.yml` files you have added, look specially for tab characters, try replacing them with spaces.

---

<div class="post-metadata">

**Author:** ![cpohl](https://avatars.discourse-cdn.com/v4/letter/c/838e76/32.png) [@cpohl](https://discuss.elastic.co/u/cpohl)\
**Post date:** [August 27, 2020, 5:16am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070/3 "2020-08-27T05:16:33Z")

</div>

Thank you very much for the hint and I have found a tab character in my fields.yml.  
Unfortunately I get now another fail by make update:

```auto
mage update
Generated fields.yml for filebeat to /srv/test/beats/filebeat/fields.yml
Generated fields.yml for filebeat to /srv/test/beats/filebeat/fields.yml
>> Building filebeat.yml for linux/amd64
>> Building filebeat.reference.yml for linux/amd64
>> Building filebeat.docker.yml for linux/amd64
exec: go list -m
Generated fields.yml for filebeat to /srv/test/beats/filebeat/build/fields/fields.all.yml
Traceback (most recent call last):
  File "/srv/test/beats/libbeat/scripts/generate_fields_docs.py", line 5, in <module>
    import yaml
ImportError: No module named 'yaml'
Error: running "/srv/test/beats/build/ve/linux/bin/python3 /srv/test/beats/libbeat/scripts/generate_fields_docs.py build/fields/fields.all.yml filebeat /srv/test/beats --output_path /srv/test/beats/filebeat" failed with exit code 1
Makefile:13: recipe for target 'update' failed
make: *** [update] Error 1

```

Is maybe my Python not correct installed?  
Can anyone help me please?  
Thanks a lot.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 27, 2020, 9:57am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070/4 "2020-08-27T09:57:22Z")

</div>

Yes, this looks like yaml is missing in the virtual environment used by mage. You can reinstall the dependencies with:

```auto
/srv/test/beats/build/ve/linux/bin/pip install -r /srv/test/beats/libbeat/tests/system/requirements.txt

```

Or if you remove the virtual environments directory (`/srv/test/beats/build/ve/` in your case), `mage` will recreate it when needed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2020, 11:57am UTC](https://discuss.elastic.co/t/filebeat-make-update-fails-for-new-custom-module/246070/5 "2020-09-24T11:57:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
