Fleet documentation
A fleet of hosts, and the services you allow on them
Fleet is one console for the machines you run. Install the Fleet connector on a machine and it appears here as a host. From the same console you allow or disallow each Wazuh product on those hosts, and the product installs its own service through Fleet.
One console for every host
The hosts you run, on your own hardware and in Wazuh Cloud, sit in one table. Open one to see its connector, its identity and the services enabled on it.
One connector, every service
The Fleet connector on a host runs the service each Wazuh product installs through Fleet. Allow a service on a host and that product installs and enrols it from its own console, with nobody logging into the machine. Wazuh Vesper, Mobius and Pharos reach your hosts this way.
Nothing connects in
The connector runs on a host inside your network and dials out to Fleet over mTLS. There is no inbound firewall rule to open. Fleet reaches your hosts only over the session the connector opens.
Fleet holds no credentials
Fleet reads a host's name, its platform and the connector on it. On a Wazuh node the installer also finds, once, the Wazuh login the host keeps and hands it only to the services installed there. That login never leaves the host, and a login set from a service replaces it.
Start here
- New to Fleet? What is Fleet explains the product and how a host, a connector and a service fit together, and the playground lets you walk every screen against sample data without installing anything.
- Ready to connect something? Add your first host, then install the connector.
- Reviewing Fleet for your security team? Read what Fleet can and cannot do and what Fleet stores.
A Wazuh product.