# Probleme winlogbeats

**URL:** <https://discuss.elastic.co/t/probleme-winlogbeats/375524>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 6, 2025, 2:16pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524 "2025-03-06T14:16:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![team\_simsim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/team_simsim/32/141852_2.png) [@team\_simsim](https://discuss.elastic.co/u/team_simsim)\
**Post date:** [March 6, 2025, 2:16pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/1 "2025-03-06T14:16:28Z")

</div>

hello

my winlogbeats clients don't want to come up when I start the service there is this error

Exiting: failed to sanitize the YAML pipeline file: security/ingest/security.yml: key 'false' is not string but bool

thanks for your help

* * *

bonjour

mon cliens winlogbeats ne veux pas remonte quand je lance le service il y a cette erreur

Exiting: failed to sanitize the YAML pipeline file: security/ingest/security.yml: key 'false' is not string but bool

merci de votre aide

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 6, 2025, 3:03pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/2 "2025-03-06T15:03:45Z")

</div>

Bonjour! 😉

Could you share your `security/ingest/security.yml` file?

---

<div class="post-metadata">

**Author:** ![team\_simsim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/team_simsim/32/141852_2.png) [@team\_simsim](https://discuss.elastic.co/u/team_simsim)\
**Post date:** [March 6, 2025, 3:22pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/3 "2025-03-06T15:22:47Z")

</div>

(post deleted by author)

---

<div class="post-metadata">

**Author:** ![team\_simsim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/team_simsim/32/141852_2.png) [@team\_simsim](https://discuss.elastic.co/u/team_simsim)\
**Post date:** [March 7, 2025, 7:39am UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/4 "2025-03-07T07:39:38Z")

</div>

I can't send the file because it is not authorized. Do you have an email address or another idea so that you can access the file?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2025, 7:54am UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/5 "2025-03-07T07:54:23Z")

</div>

Oui. You send me a private message with it. Click on my profile and then Message.

---

<div class="post-metadata">

**Author:** ![team\_simsim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/team_simsim/32/141852_2.png) [@team\_simsim](https://discuss.elastic.co/u/team_simsim)\
**Post date:** [March 7, 2025, 8:22am UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/7 "2025-03-07T08:22:02Z")

</div>

I'll send them to you on slack.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2025, 1:13pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/8 "2025-03-07T13:13:03Z")

</div>

I suspect here the usage of `ignore_failure: "true"` instead of `ignore_failure: true`.  
AFAICS in the provided private config file.

---

<div class="post-metadata">

**Author:** ![mellanvidia](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@mellanvidia](https://discuss.elastic.co/u/mellanvidia)\
**Post date:** [March 9, 2025, 5:12pm UTC](https://discuss.elastic.co/t/probleme-winlogbeats/375524/9 "2025-03-09T17:12:21Z")

</div>

I'm getting the same error message during CLI setup of 8.17.3. Appears to be a bug per this GitHub issue:

> <https://github.com/elastic/beats/issues/42902>
>
> \*\*Kibana Build details:\*\*
> \`\`\`
> VERSION: 9.0.0-rc1-BC1
> BUILD: 83822
> COMMIT: 07dc0a…fa460bddff658ee6d5342ad1f087fc766b
> \`\`\`
> Artifact Link: https://staging.elastic.co/9.0.0-rc1-bd80e8a3/downloads/beats/winlogbeat/winlogbeat-9.0.0-rc1-windows-x86\_64.zip
> 
> \*\*Preconditions:\*\*
> 1. 9.0.0-rc1-BC1 Kibana cloud environment should be available.
> 
> \*\*Steps to reproduce:\*\*
> 1. Update cloud id and cloud auth for winlogbeat.
> 2. Now run: \`.\\winlogbeat.exe setup\`.
> 3. Observe error under CLI: \`Exiting: failed to sanitize the YAML pipeline file: security/ingest/security.yml: key 'false' is not string but bool\`.
> 4. Now run: Start-Service winlogbeat.
> 5. Observe no data under Discover tab is displayed.
> 
> 
> \*\*Expected Result:\*\*
> No errors should be observed on running setup command for winlogbeat and data should be displayed under Discover tab.
> 
> \*\*Logs:\*\*
> \[winlogbeat-20250226.ndjson.zip\](https://github.com/user-attachments/files/18980557/winlogbeat-20250226.ndjson.zip)
> 
> 
> \*\*Screenshot:\*\*
> 
> !\[Image\](https://github.com/user-attachments/assets/e35cd947-414c-42be-9802-2a432e7b687f)
> 
> !\[Image\](https://github.com/user-attachments/assets/bb6fd267-c82a-4e1d-9088-6055c41a4b42)
