# Filebeats : failed to start found a tab character

**URL:** <https://discuss.elastic.co/t/filebeats-failed-to-start-found-a-tab-character/119461>\
**Category:** Beats\
**Created:** [February 12, 2018, 11:48am UTC](https://discuss.elastic.co/t/filebeats-failed-to-start-found-a-tab-character/119461 "2018-02-12T11:48:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pierre\_What\_s\_Up\_Sca](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@Pierre\_What\_s\_Up\_Sca](https://discuss.elastic.co/u/Pierre_What_s_Up_Sca)\
**Post date:** [February 12, 2018, 11:48am UTC](https://discuss.elastic.co/t/filebeats-failed-to-start-found-a-tab-character/119461/1 "2018-02-12T11:48:22Z")

</div>

Hi !

When I try to launch filebeat I have this error message :

```auto
< Feb 12 11:49:40 localhost.localdomain systemd[1]: Unit filebeat.service entered failed state.
Feb 12 11:49:40 localhost.localdomain systemd[1]: filebeat.service failed.
Feb 12 11:49:40 localhost.localdomain systemd[1]: filebeat.service holdoff time over, scheduling restart.
Feb 12 11:49:40 localhost.localdomain systemd[1]: Started filebeat.
Feb 12 11:49:40 localhost.localdomain systemd[1]: Starting filebeat...
Feb 12 11:49:40 localhost.localdomain filebeat[52004]: Loading config file error: YAML config parsing failed on /etc/filebeat/filebeat.yml: yaml: line 15: found a tab character that violate indentation. Exiting.
Feb 12 11:49:40 localhost.localdomain systemd[1]: filebeat.service: main process exited, code=exited, status=1/FAILURE /> 

```

It's arrived when I add TLs certificate :

```auto
filebeat:
  # List of prospectors to fetch data.
  prospectors:
    # Each - is a prospector. Below are the prospector specific configurations
    -
      # Paths that should be crawled and fetched. Glob based paths.
      # To fetch all ".log" files from a specific level of subdirectories
      # /var/log/*/*.log can be used.
      # For each file found under this path, a harvester is started.
      # Make sure not file is defined twice as this can lead to unexpected behaviour.
      paths:
        - /var/log/*.log
        - /var/log/secure
        - /var/log/messages
        #- c:\programdata\elasticsearch\logs\*
      # Type to be published in the 'type' field. For Elasticsearch output,
      # the type defines the document type these entries should be stored
      # in. Default: log
      document_type: syslog
# Optional index name. The default index name depends on the each beat.
    # For Packetbeat, the default is set to packetbeat, for Topbeat
    # top topbeat and for Filebeat to filebeat.
    #index: filebeat

    # Optional TLS. By default is off.
    tls:
      certificate_authorities: ["/etc/ssl/logstash_frwrd.crt"]

      # Certificate for TLS client authentication
      #certificate: "/etc/pki/client/cert.pem"

```

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 12, 2018, 1:07pm UTC](https://discuss.elastic.co/t/filebeats-failed-to-start-found-a-tab-character/119461/2 "2018-02-12T13:07:35Z")

</div>

The error means that you inserted a \t character in YAML. You should just replace that with spaces. Just google how to do that in your editor or use [expand](https://linux.die.net/man/1/expand), then double check that the indentation looks right.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2018, 11:48am UTC](https://discuss.elastic.co/t/filebeats-failed-to-start-found-a-tab-character/119461/3 "2018-03-05T11:48:53Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
