# Loading config file error: YAML config parsing failed on /usr/local/etc/filebeat.yml

**URL:** <https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 23, 2016, 11:27pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755 "2016-08-23T23:27:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![reo7189](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@reo7189](https://discuss.elastic.co/u/reo7189)\
**Post date:** [August 23, 2016, 11:27pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/1 "2016-08-23T23:27:15Z")

</div>

FreeBSD 10.3, filebeat 1.2.3, when trying "service filbert start" I got endless error "Loading config file error: YAML config parsing failed on /usr/local/etc/filebeat.yml: yaml: line 7: found character that cannot start any token. Exiting."

What's wrong with this, [ls help. my filebeat.yml is as below:

```auto
################### Filebeat Configuration #########################

############################# Filebeat ######################################
filebeat:
  prospectors:
    -
      paths:
        - /var/log/messages
        - /var/log/security

      input_type: log
      document_type: syslog

############################# Output ##########################################

output:

  ### Logstash as output
  logstash:
    # The Logstash hosts
    hosts: ["192.168.11.24:5044"]
    bulk_max_size: 1024

    # Optional TLS. By default is off.
   tls:
      certificate_authorities: ["/usr/local/etc/logstash/logstash-forwarder.crt"]

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2016, 5:49am UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/2 "2016-08-24T05:49:42Z")

</div>

YAML is sensitive to indentation so you must make sure the indentation is preserved when you post here. Otherwise it's impossible to tell what's wrong. Paste your configuration again and make sure it's formatted as code (use the toolbar button). A service like [http://www.yamllint.com/](http://www.yamllint.com/) might also be helpful.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 24, 2016, 10:47am UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/3 "2016-08-24T10:47:46Z")

</div>

I did try to 'reformat' your post a little. But due to copy'n paste I can not if any special symbols/characters are missing. I see the `tls` option not being properly indented, but in original file there might be other errors.

---

<div class="post-metadata">

**Author:** ![reo7189](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@reo7189](https://discuss.elastic.co/u/reo7189)\
**Post date:** [August 24, 2016, 1:10pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/4 "2016-08-24T13:10:32Z")

</div>

```
################### Filebeat Configuration #########################

############################# Filebeat ######################################
filebeat:
  prospectors:
    -
      paths:
        - /var/log/messages
        - /var/log/security

      input_type: log
      document_type: syslog
############################# Output ##########################################

output:

  ### Logstash as output
  logstash:
    hosts: ["192.168.11.24:5044"]
    bulk_max_size: 1024

   tls:
      certificate_authorities: ["/usr/local/etc/logstash/logstash-forwarder.crt"]
```

---

<div class="post-metadata">

**Author:** ![reo7189](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@reo7189](https://discuss.elastic.co/u/reo7189)\
**Post date:** [August 24, 2016, 1:13pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/5 "2016-08-24T13:13:25Z")

</div>

Sorry, but do you mean copy/paste and then use `Performated Text`? as i pasted above?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2016, 1:24pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/6 "2016-08-24T13:24:28Z")

</div>

> Sorry, but do you mean copy/paste and then use Performated Text? as i pasted above?

Yes. As @steffens noted the "tls:" line is incorrectly indented. Start by fixing that.

---

<div class="post-metadata">

**Author:** ![reo7189](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@reo7189](https://discuss.elastic.co/u/reo7189)\
**Post date:** [August 24, 2016, 2:03pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/7 "2016-08-24T14:03:59Z")

</div>

Thank you very much. My mistakes due to less knowledge of YAML. With the help of you I finally got it solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2016, 11:27pm UTC](https://discuss.elastic.co/t/loading-config-file-error-yaml-config-parsing-failed-on-usr-local-etc-filebeat-yml/58755/8 "2016-09-13T23:27:26Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
