# Missing field accessing 'path' accessing 'filebeat' (source:'filebeat.yml')

**URL:** <https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 21, 2017, 3:29pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849 "2017-12-21T15:29:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [December 21, 2017, 3:29pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/1 "2017-12-21T15:29:49Z")

</div>

Trying to work out why filebeat 6.1.0 is not shipping logs and ran the following from powershell `.\filebeat -v -e -d "config"` and this was returned:

```
PS D:\Program Files\filebeat-6.1.0> .\filebeat -v -e -d "config"
filebeat2017/12/21 15:07:23.997253 config.go:214: DBG [config] load config file 'filebeat.yml' =>
<config error> missing field accessing 'path' accessing 'filebeat' (source:'filebeat.yml')
filebeat2017/12/21 15:07:24.003355 config.go:214: DBG [config] Complete configuration loaded:
{
  "filebeat": {
    "config": {
      "modules": {
        "path": "D:\\Program Files\\filebeat-6.1.0/modules.d/*.yml",
        "reload": {
          "enabled": false
        }
      }
    },
    "prospectors": [
      {
        "enabled": true,
        "exclude_lines": [
          "#"
        ],
        "paths": [
          "d:\\Inetpub\\logs\\logfiles\\*\\*"
        ],
        "type": "log"
      }
    ]
  },
  "logging": {
    "files": {
      "keepfiles": 7,
      "name": "mybeat.log",
      "path": "D:\\Program Files\\filebeat-6.1.0\\log"
    },
    "level": "warning",
    "to_files": true,
    "to_syslog": false
  },
  "output": {
    "logstash": {
      "hosts": [
        "xxxxx"
      ],
      "index": "filebeat_iis"
    }
  },
  "path": {
    "config": "D:\\Program Files\\filebeat-6.1.0",
    "data": "D:\\Program Files\\filebeat-6.1.0\\data",
    "home": "D:\\Program Files\\filebeat-6.1.0",
    "logs": "D:\\Program Files\\filebeat-6.1.0\\logs"
  },
  "setup": {
    "kibana": null,
    "template": {
      "settings": {
        "index": {
          "number_of_shards": 3
        }
      }
    }
  },
  "tags": [
    "iis-logs"
  ]
}

```

What does this mean `missing field accessing 'path' accessing 'filebeat' (source:'filebeat.yml')`?

---

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [December 21, 2017, 3:35pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/2 "2017-12-21T15:35:05Z")

</div>

Additional:

```
2017/12/21 15:07:24.179870 metrics.go:23: INFO Metrics logging every 30s
2017/12/21 15:07:24.179870 beat.go:436: INFO Home path: [D:\Program Files\filebeat-6.1.0] Config path: [D:\Program Files
\filebeat-6.1.0] Data path: [D:\Program Files\filebeat-6.1.0\data] Logs path: [D:\Program Files\filebeat-6.1.0\logs]
2017/12/21 15:07:24.182867 beat.go:443: INFO Beat UUID: 7f14eae6-4592-4dc4-be2e-7cccadd4cc5f
2017/12/21 15:07:24.183869 beat.go:203: INFO Setup Beat: filebeat; Version: 6.1.0
2017/12/21 15:07:24.189145 module.go:76: INFO Beat name: hemera
2017/12/21 15:07:24.194116 beat.go:276: INFO filebeat start running.
2017/12/21 15:07:24.267673 registrar.go:88: INFO Registry file set to: D:\Program Files\filebeat-6.1.0\data\registry
2017/12/21 15:07:24.280840 registrar.go:108: INFO Loading registrar data from D:\Program Files\filebeat-6.1.0\data\regis
try
2017/12/21 15:07:24.287736 registrar.go:119: INFO States Loaded from registrar: 52
2017/12/21 15:07:24.288763 registrar.go:150: INFO Starting Registrar
2017/12/21 15:07:24.288763 filebeat.go:261: WARN Filebeat is unable to load the Ingest Node pipelines for the configured
 modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipeline
s or are using Logstash pipelines, you can ignore this warning.
2017/12/21 15:07:24.312996 crawler.go:48: INFO Loading Prospectors: 1
2017/12/21 15:07:24.410150 prospector.go:87: INFO Starting prospector of type: log; ID: 9709682197378411112
2017/12/21 15:07:24.419968 crawler.go:82: INFO Loading and starting Prospectors completed. Enabled prospectors: 1
2017/12/21 15:07:24.419968 reload.go:127: INFO Config reloader started
2017/12/21 15:07:24.424963 reload.go:219: INFO Loading of config files completed.
```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 26, 2017, 9:17pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/3 "2017-12-26T21:17:31Z")

</div>

Can you share your `filebeat.yml` file?

---

<div class="post-metadata">

**Author:** ![teejayuu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teejayuu/32/18356_2.png) [@teejayuu](https://discuss.elastic.co/u/teejayuu)\
**Post date:** [January 4, 2018, 1:45pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/4 "2018-01-04T13:45:08Z")

</div>

Thanks ruflin, sorry for the delay...holidays etc. Here is my `filebeat.yml`:

```
filebeat.prospectors:
- type: log
  enabled: true
  paths:
    - d:\Inetpub\logs\logfiles\*\*
  exclude_lines: ['#']
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
setup.template.settings:
  index.number_of_shards: 3
tags: ["iis-logs"]
setup.kibana:
output.logstash:
  hosts: ["scamander.hstv.local:5044"]
  index: "filebeat_iis"
logging.level: warning
logging.to_files: true
logging.to_syslog: false
logging.files:
  path: D:\Program Files\filebeat-6.1.0\log
  name: mybeat.log
  keepfiles: 7

```

Thanks

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 9, 2018, 4:59am UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/5 "2018-01-09T04:59:58Z")

</div>

I wonder if one of the following paths cannot be accessed:

```auto
    "config": "D:\\Program Files\\filebeat-6.1.0",
    "data": "D:\\Program Files\\filebeat-6.1.0\\data",
    "home": "D:\\Program Files\\filebeat-6.1.0",
    "logs": "D:\\Program Files\\filebeat-6.1.0\\logs"

```

Do these directories all exist. @steffens might know more about the log message.

But TBH I don't think this is related to why Filebeat does not ship logs. Based on the log output you posted above all looks normal.

How do you update your log file?  
Can share a bit more of your log file on how it looks after 2-3 minutes? There should be an output every 30s with some stats.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 9, 2018, 2:46pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/6 "2018-01-09T14:46:14Z")

</div>

The message seems to be related to debug output only. Might be we have a debug statement trying to print a yet incomplete filebeat configuration (right after reading filebeat.yml, the `paths` namespace is not yet available). But after merging all settings, the debug creates a valid config (printed as JSON), with all path configs being properly expanded.

I wonder if a) there is actually an harvester running b) we have errors in the output. The sample startup logs don't draw a complete picture yet.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2018, 2:46pm UTC](https://discuss.elastic.co/t/missing-field-accessing-path-accessing-filebeat-source-filebeat-yml/112849/7 "2018-02-06T14:46:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
