# Indentation error on filebeat conf

**URL:** <https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 23, 2022, 3:09pm UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033 "2022-06-23T15:09:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guillaume\_D](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@Guillaume\_D](https://discuss.elastic.co/u/Guillaume_D)\
**Post date:** [June 23, 2022, 3:09pm UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033/1 "2022-06-23T15:09:13Z")

</div>

Hi, I want to do some basic process with filebeat on my logs but I have some indentations problemes I just don't know how to resolve.

Here is the current stat of the conf file, input and output has been sensored but I already know the problems are in the processors

```auto

processors:
  - if: 
      contains:
        log.file.path: "path1"
    then:
      - drop_event:
          when:
            - regexp:
              message: "^!"
        #create criticity and clean messsage field 
      - dissect:
          tokenizer: "[%{criticity}] [%{timestamp}] %{msg}"
          field: "message"
          target_prefixe: ""
          overwrite_keys: true
      - drop_field:
          fields: ["message"]
      - rename:
          fields:
            - from: "msg"
              to: "message"
          ignore_missing: true
          fail_on_error: true
  - if: 
      contains:
        log.file.path: "path2"
    then:
      - dissect:
          tokenizer: '%{ip_adresse} - - [%{@timestamp}] "%{verb} / %{target}" %{return_code|integer} %{answer_lenght|integer} "%{}" "%{?%referer}" %{call_lenght|integer}'
          field: "message"
          target_prefixe: ""
          overwrite_keys: true

```

and here is my current error :

filebeat]# filebeat test config -c filebeat.yml  
Exiting: error initializing processors: failed to make if/then/else processor: failed to initialize condition: missing or invalid condition

---

<div class="post-metadata">

**Author:** ![sudhagar\_ramesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhagar_ramesh/32/105673_2.png) [@sudhagar\_ramesh](https://discuss.elastic.co/u/sudhagar_ramesh)\
**Post date:** [June 24, 2022, 3:57am UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033/2 "2022-06-24T03:57:59Z")

</div>

Hello @Guillaume_D

Welcome to Elastic Community 😃 !!!

There are no indentation error. You can also validate your code using any of yml validator.  
The error message means that there is an invalid condition specified in processors.

When using if-then-else processors we should not use **when** for the conditions

Hence try the below

```auto
processors:
  - if: 
      contains:
        log.file.path: "path1"
    then:
      - drop_event:
            - regexp:
              message: "^!"

```

if this above code block doesn't work then change your code accordingly but without using "when"

For more information , refer the below links:

> **[Define processors | Filebeat Reference \[8.2\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html)**

Keep Posted !!! Thanks !!!

---

<div class="post-metadata">

**Author:** ![Guillaume\_D](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@Guillaume\_D](https://discuss.elastic.co/u/Guillaume_D)\
**Post date:** [June 24, 2022, 8:10am UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033/3 "2022-06-24T08:10:59Z")

</div>

Thanks @sudhagar_ramesh the file conf dooesn't show error anymore !  
Small probleme is it doesn't do what it was made for, none of the processors inside the if are used.

Ther may be a probleme in the condition. the file path I must spécifie in my condition is the one of the log file were I get my logs from right ?

current stat of the conf:  
`#processors for Oscare  
processors:

- if:  
contains:  
log.file.path: "path1"  
then:
  - drop\_event:  
- regexp:  
message: "^!"  
#create criticity and clean messsage field
  - dissect:  
tokenizer: "[%{criticity}] [%{timestamp}] %{msg}"  
field: "message"  
target\_prefixe: ""  
overwrite\_keys: true
  - drop\_field:  
fields: ["message"]
  - rename:  
fields:  
- from: "msg"  
to: "message"  
ignore\_missing: true  
fail\_on\_error: true

- if:  
contains:  
log.file.path: "path2"  
then:
  - dissect:  
tokenizer: '%{ip\_adresse} - - [%{@timestamp}] "%{verb} / %{target}" %{return\_code|integer} %{answer\_lenght|integer} "%{}" "%{?%referer}" %{call\_lenght|integer}'  
field: "message"  
target\_prefixe: ""  
overwrite\_keys: true`

---

<div class="post-metadata">

**Author:** ![sudhagar\_ramesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhagar_ramesh/32/105673_2.png) [@sudhagar\_ramesh](https://discuss.elastic.co/u/sudhagar_ramesh)\
**Post date:** [June 24, 2022, 9:03am UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033/4 "2022-06-24T09:03:55Z")

</div>

Hello @Guillaume_D

Yes, you should also have to make the change in the log.file.path

that should be like

```auto
  - if: 
      contains:
          paths:
	    - /var/log/messages

```

Keep Posted!!! Thanks !!!

For more information about path, refer below link

> **[Log input | Filebeat Reference \[8.2\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html)**

---

<div class="post-metadata">

**Author:** ![Guillaume\_D](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@Guillaume\_D](https://discuss.elastic.co/u/Guillaume_D)\
**Post date:** [June 24, 2022, 4:58pm UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033/5 "2022-06-24T16:58:55Z")

</div>

thanks @sudhagar_ramesh it all works now!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2022, 6:59pm UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033/6 "2022-07-22T18:59:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
