# Winlogbeats 5 processors configuration question

**URL:** <https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648>\
**Category:** Beats\
**Created:** [September 27, 2016, 10:12pm UTC](https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648 "2016-09-27T22:12:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [September 27, 2016, 10:12pm UTC](https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648/1 "2016-09-27T22:12:49Z")

</div>

We've been using winlogbeat 1.3 for months now and have wanted to be able to pre-process the data shipped by event and trim the fields sent. Seems like the new features in the Beta 5 would offer this. I am getting an error in my yml file (yaml: control characters are not allowed) - i have used yamllint to verify it's okay.

I wonder how strict the parser is and whether a more descriptive error could be provided.

First, i see variations in the formatting of processors in documentation - i have tried several permeations: online there are 2 spaces before the - for drop\_fields and then 2 more spaces before the fields. In the example yml files (winlogbeat.full.yml) there is no apparent space before the - before the drop\_fields.

Another inconsistency I am unsure matters is sometimes the field names are quoted (winlogbeat.full.yml) and sometimes they are not (filtering-and-enhancing-data.html).

---

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [September 27, 2016, 10:15pm UTC](https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648/2 "2016-09-27T22:15:33Z")

</div>

Okay, all that may have been a red herring. I found the problem was (or appears to have been) that my .winlogbeat.yml file was somehow corrupted. Not sure how this would happen....

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 28, 2016, 10:47am UTC](https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648/3 "2016-09-28T10:47:03Z")

</div>

What version of Winlogbeat were you running when this problem occurred?

---

<div class="post-metadata">

**Author:** ![cord\_thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cord_thomas/32/8009_2.png) [@cord\_thomas](https://discuss.elastic.co/u/cord_thomas)\
**Post date:** [September 28, 2016, 3:29pm UTC](https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648/4 "2016-09-28T15:29:00Z")

</div>

winlogbeat 5.0.0 beta1 downloaded yesterday. 64-bit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2016, 10:13pm UTC](https://discuss.elastic.co/t/winlogbeats-5-processors-configuration-question/61648/5 "2016-10-18T22:13:25Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
