# Unable to start Filebeat due to YAML config issue

**URL:** <https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-yaml-config-issue/75875>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2017, 12:38pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-yaml-config-issue/75875 "2017-02-21T12:38:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ohk](https://avatars.discourse-cdn.com/v4/letter/o/dec6dc/32.png) [@ohk](https://discuss.elastic.co/u/ohk)\
**Post date:** [February 21, 2017, 12:38pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-yaml-config-issue/75875/1 "2017-02-21T12:38:35Z")

</div>

Hi  
I have this Filebeat configuration :

```
- input_type: log
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /home/ohk/data/nginx.log
  document_type: nginx #line 22
  multiline.pattern: ["^(\b(?:\d{1,3}\.){3}\d{1,3}\b)"]
  multiline.negate: false
  multiline.match: after
  #############################################################
  paths:
    - /home/ohk/data/api.log
  document_type: api
  multiline.pattern: ["^(INFO in )"]
  multiline.negate: false
  multiline.match: after

```

when I try to start my filebeat service I get this error:

Exiting: error loading config file: yaml: line 22: found unknown escape character  
I marked line 22 in the example above, and I checked that all indents are spaces only. Do you have any idea about this unknown escape character ?

Thank you in advance,

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 21, 2017, 2:42pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-yaml-config-issue/75875/2 "2017-02-21T14:42:55Z")

</div>

Uhm... do you count lines from 0 or 1... TBH I'm not sure if the yaml parser counts from 0 or 1 🙂

My initial guess it's due to quoting the regex with `"` . When you use `"`, the yaml parser interprets the strings content , treating `\b, \d` and such as escape characters. Using single quotes `'` (as recommended in our docs) to not have the yaml parser interpret the regular expression.

---

<div class="post-metadata">

**Author:** ![ohk](https://avatars.discourse-cdn.com/v4/letter/o/dec6dc/32.png) [@ohk](https://discuss.elastic.co/u/ohk)\
**Post date:** [February 21, 2017, 3:47pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-yaml-config-issue/75875/3 "2017-02-21T15:47:48Z")

</div>

Thank you, you're right I used go-to-line from nano so I was one line above the real problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2017, 3:48pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-due-to-yaml-config-issue/75875/4 "2017-03-21T15:48:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
