# Need help with errors during starting filebeat service, please help with verifying the yml file

**URL:** <https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 10, 2019, 3:59am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654 "2019-01-10T03:59:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![clouddev](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@clouddev](https://discuss.elastic.co/u/clouddev)\
**Post date:** [January 10, 2019, 3:59am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654/1 "2019-01-10T03:59:56Z")

</div>

When I am trying to start the filebeat service I get an error saying..

```
graylog@graylog:/etc/filebeat$ service filebeat status
● filebeat.service - filebeat
   Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; vendor preset: enabled)
   Active: failed (Result: start-limit-hit) since Wed 2019-01-09 20:59:32 CST; 1s ago
     Docs: https://www.elastic.co/guide/en/beats/filebeat/current/index.html
  Process: 4650 ExecStart=/usr/share/filebeat/bin/filebeat -c /etc/filebeat/filebeat.yml -path.home /usr/share/filebeat -path.config /etc/filebeat -path.data /var/lib/fi
 Main PID: 4650 (code=exited, status=1/FAILURE)

Jan 09 20:59:31 graylog systemd[1]: filebeat.service: Unit entered failed state.
Jan 09 20:59:31 graylog systemd[1]: filebeat.service: Failed with result 'exit-code'.
Jan 09 20:59:32 graylog systemd[1]: filebeat.service: Service hold-off time over, scheduling restart.
Jan 09 20:59:32 graylog systemd[1]: Stopped filebeat.
Jan 09 20:59:32 graylog systemd[1]: filebeat.service: Start request repeated too quickly.
Jan 09 20:59:32 graylog systemd[1]: Failed to start filebeat.
Jan 09 20:59:32 graylog systemd[1]: filebeat.service: Unit entered failed state.
Jan 09 20:59:32 graylog systemd[1]: filebeat.service: Failed with result 'start-limit-hit'.

```

Here is the yml file. Can you help see if this is an issue with spacing or unwanted characters, or even identation in this script.

```
filebeat.prospectors:
- input_type: log
document_type: postfix
paths:
- /var/log/mail.log
- input_type: log
document_type: zimbra_audit
paths:
- /opt/zimbra/log/audit.log
- input_type: log
document_type: zimbra_mailbox
paths:
- /opt/zimbra/log/mailbox.log
- input_type: log
document_type: nginx
paths:
- /opt/zimbra/log/nginx.access.log
output.logstash:
  hosts: ["192.168.1.27:5045"]
  template.name: "filebeat"
  template.path: "filebeat.template.json"
  template.overwrite: false
output.elasticsearch:
  hosts: ["localhost:9200"]
logging.metrics.period: 1m

```

I am sorry If i am breaking any rules here, I am new to this technology and to the forum.  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![clouddev](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@clouddev](https://discuss.elastic.co/u/clouddev)\
**Post date:** [January 10, 2019, 4:15am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654/2 "2019-01-10T04:15:52Z")

</div>

Does it have to do with the depreciated document\_type and input\_type parameters?  
If so, then what would be correct way to put all of this?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 11, 2019, 2:18am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654/3 "2019-01-11T02:18:04Z")

</div>

Hello, I see a few errors, input declaration should be defined similar to this:

```auto
filebeat.inputs:
    - type: log
      paths:
        - /var/log/mail.log
      fields:
        document_type: postfix

    - type: log
      paths:
        - /opt/zimbra/log/audit.log
      fields:
        document_type: zimbra_audit
    - type: log
      paths:
        - /opt/zimbra/log/mailbox.log
      fields:
        document_type: zimbra_mailbox

    - type: log
      paths:
        - /opt/zimbra/log/nginx.access.log
      fields:
        document_type: nginx

```

And filebeat only support one output defined at any time:

```auto
output.logstash:
  hosts: ["192.168.1.27:5045"]

```

Or

```auto
output.elasticsearch:
  hosts: ["localhost:9200"]

```

You can test your configuration by running filebeat in shell and increase the log level, the following command should give more information:

```auto
filebeat -v -e -d "*"

```

---

<div class="post-metadata">

**Author:** ![clouddev](https://avatars.discourse-cdn.com/v4/letter/c/a9adbd/32.png) [@clouddev](https://discuss.elastic.co/u/clouddev)\
**Post date:** [January 12, 2019, 5:10am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654/4 "2019-01-12T05:10:49Z")

</div>

> [@pierhugues](#):
>
> filebeat.inputs: - type: log paths: - /var/log/mail.log fields: document\_type: postfix - type: log paths: - /opt/zimbra/log/audit.log fields: document\_type: zimbra\_audit - type: log paths: - /opt/zimbra/log/mailbox.log fields: document\_type: zimbra\_mailbox - type: log paths: - /opt/zimbra/log/nginx.access.log fields: document\_type: nginx

Thanks for setting this up for me. I am gonna try this, and report back.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2019, 5:10am UTC](https://discuss.elastic.co/t/need-help-with-errors-during-starting-filebeat-service-please-help-with-verifying-the-yml-file/163654/5 "2019-02-09T05:10:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
