# Filebeat on Windows - do not start

**URL:** <https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 9, 2018, 11:55am UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037 "2018-11-09T11:55:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![picoroma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/picoroma/32/37634_2.png) [@picoroma](https://discuss.elastic.co/u/picoroma)\
**Post date:** [November 9, 2018, 11:55am UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037/1 "2018-11-09T11:55:06Z")

</div>

I'm trying to configure filebeats on a windows server where is running Tomcat 8.5.  
The goal is to send Tomcat log files to Elasticsearch or to Logstash.  
I Have, for this installed and configured an ELK stack.  
So, ES, Logstash and Kibana are installed on same LINUX server and Filebeats on Windows.

The filebeat.yml is quite simple:  
Firts I have this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b30d55eee790a2494aa30dfcbc99277004bfc824.png)

And then as output, I'm trying to use ES and KIBANA  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/052e6df7f20bec7b8cf6202b037a6fedc9e4d060.png)

When I try to start the filebeat from a command prompt of windows:

c:\Program\filebeat\>filebeat.exe -c filebeat.yml -e  
I have this kind of error:

> 2018-11-09T12:53:43.814+0100 INFO instance/beat.go:286 Setup Beat: filebeat; Version: 6.4.3  
> 2018-11-09T12:53:43.815+0100 INFO elasticsearch/client.go:163 Elasticsearch url: [http://172.30.6.64:9200](http://172.30.6.64:9200)  
> 2018-11-09T12:53:43.817+0100 INFO pipeline/module.go:98 Beat name: EC2AMAZ-DV55646  
> 2018-11-09T12:53:43.818+0100 INFO instance/beat.go:340 filebeat stopped.  
> 2018-11-09T12:53:43.819+0100 ERROR instance/beat.go:764 Exiting: Error reading config file: required 'object', but found 'string' in field 'filebeat.inputs.1' (source:'filebeat.yml')  
> Exiting: Error reading config file: required 'object', but found 'string' in field 'filebeat.inputs.1' (source:'filebeat.yml')

Where I was wrong ?  
THX  
P.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 9, 2018, 11:59am UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037/2 "2018-11-09T11:59:11Z")

</div>

Please do not paste screenshot of your configuration. Rhater copy it here and format the text using `</>`.

The indentation of `document_type` seems to be incorrect.

```auto
filebeat.inputs:
- type: log
  enabled: false
  paths:
    - C:\....
  document_type: apachelogs

```

---

<div class="post-metadata">

**Author:** ![picoroma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/picoroma/32/37634_2.png) [@picoroma](https://discuss.elastic.co/u/picoroma)\
**Post date:** [November 12, 2018, 3:59pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037/3 "2018-11-12T15:59:33Z")

</div>

I have this, now:

```
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

- type: log
  # Change to true to enable this input configuration.
  enabled: true
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    #- /var/log/*.log
    #- c:\programdata\elasticsearch\logs\*
    - 'D:\xampp\apache\logs\*.log'
    document_type: apachelogs

```

But still have error if run  
./filebeats.exe setup -e

Exiting: error loading config file: yaml: line 28: did not find expected '-' indicator  
Line 28 is the line with path.  
I tried even without "-" at the beginning of line but I have another error (same line):  
Exiting: error loading config file: yaml: line 28: did not find expected key

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 12, 2018, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037/4 "2018-11-12T21:06:38Z")

</div>

YAML is sensitive to indentation. You have one `-` at one line and the next line you start a dictionary. You can not mix dictionary and lists in one namespace in yaml.

I think it must say:

```auto
- type: log
  # Change to true to enable this input configuration.
  enabled: true
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    #- /var/log/*.log
    #- c:\programdata\elasticsearch\logs\*
    - 'D:\xampp\apache\logs\*.log'
  document_type: apachelogs

```

The `document_type` must be on the same level as `paths`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2018, 9:06pm UTC](https://discuss.elastic.co/t/filebeat-on-windows-do-not-start/156037/5 "2018-12-10T21:06:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
