Your own hosts
A host of your own is a machine you run, reached through a connector you install on it, inside your own network. You add the host in Fleet, Fleet mints an enrollment token, you run one command on the machine, and the connector dials out to Fleet and holds the session open. It reports the host and runs the services you allow on it.
Nothing connects into your network at any point, so there is no inbound firewall rule to add, no port to publish and no address to expose. The other kind of row, found in your Wazuh Cloud account, is Wazuh Cloud environments.
Adding one
Open Hosts and press Add a host, or use the same button on the Overview. Name the host and press Add host. This needs an admin role or the add-hosts permission on your membership; see Team and roles.
The name is yours to choose and the machine name is the useful one, because it is what the table shows beside the hostname the connector reports.
The host exists the moment the API answers, listed as Not connected. Fleet mints a single-use enrollment token, stores only its SHA-256 hash, and shows the one-liner once:
curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<ENROLLMENT_TOKEN>
Run it as root on a Linux machine with systemd. The installer verifies the
binary's published checksum, stages the gateway CA, writes
/etc/fleet-connector/connector.yaml, enrols, looks once for the Wazuh login
the host keeps, and starts the service. It asks nothing and takes no typed
credentials of any kind. The login it finds stays on the host, for the services
installed there through Fleet. See
The Wazuh login the installer finds.
Install the connector is the full procedure.
The connector generates its own key pair on the machine, sends a certificate request with the token, and receives a client certificate whose subject carries its connector id, your tenant and this host. The private key never leaves the machine. On its first heartbeat the host becomes Connected, and the page takes you to it.
It is shown once, only its hash is stored, and the first enrolment that redeems it consumes it. If the hour passes before you reach the machine, open the host and press Get the install command to mint a fresh one. A token enrols one machine: adding a second host means adding it in Fleet, with its own name and its own token.
One host, one connector
A host in Fleet is one machine running one connector. The enrollment token is single use, and the gateway keeps one live session per host, so a second connector dialling for the same host supersedes the first, whose session is closed.
A distributed Wazuh deployment is therefore not one row. Each machine you want Fleet to reach is its own host, added and installed on its own, and each appears in the table with what it last reported.
A host's page
See detail, from the table or from a card on the Overview, opens the host's own page.
Information carries its name, its kind and its Fleet id. In Fleet is the link itself: the status, when it was added, the connector's id, and the data path, which reads "Running in your network, dialing the Fleet gateway outbound." The Remove from Fleet control lives there, and Remove a host is what it does.
Host details is what the connector last reported.
| Field | What the host reports |
|---|---|
| Status | Online or Offline |
| Last heartbeat | How long ago it checked in, or never for a connector that enrolled and has not beaten yet |
| Platform | The operating system and architecture, for example Ubuntu 24.04 LTS · linux/amd64 |
| Connector | The connector version it is running, or unknown |
| Hostname | The name the machine reports for itself |
| Identity | The client certificate's remaining life, described below |
Before any connector has enrolled the card says so plainly: No connector has enrolled for this host yet. Run the installer on the machine; it appears here on its first heartbeat. A read that fails renders no fields at all, only a sentence naming the layer that refused: an empty card and one that could not be loaded look identical, and only one means the connector never reported.
Under those fields, the services enabled on the host are listed, each with its own state. A service that is not healthy says why in its own words, and one whose status Fleet cannot read at all reads as unknown rather than bad. Fleet reports whether a service's process is alive and enrolled on that machine. Whether the product itself is working is that product's own console. See Other Wazuh products on your hosts.
Online means a heartbeat inside 90 seconds
The connector heartbeats every 30 seconds by default, configurable as
heartbeat_seconds in /etc/fleet-connector/connector.yaml. Fleet reads a host
as Online while its last heartbeat is younger than 90 seconds, three beats at
that default. The API sends that window with the rows and the page re-derives
Online against the browser's clock, so a page left open ages instead of freezing
on the answer it was given when it loaded.
Two other timers sit around that one. The gateway drops a session that has sent nothing for 75 seconds, deliberately below the 90, so the sessions the gateway believes in are always a subset of what the console shows as connected. The connector's own watchdog ends a session when three heartbeat intervals pass with no acknowledgement, and redials.
A host that stops reporting keeps its row. The dot goes grey, the status reads Offline and the last heartbeat ages, while every other field still shows what the final heartbeat said: history rather than the present, and the timestamp beside the status is what tells you which. The host's own status follows the same window:
| Status | What it means |
|---|---|
| Not connected | The host exists in Fleet and no connector has enrolled for it |
| Connecting | A connector redeemed the token and has not sent a heartbeat yet |
| Connected | A heartbeat arrived within the last 90 seconds |
| Disconnected | A connector has beaten before and none has beaten within the window |
Connected and Disconnected are worked out from the connector rows on every read rather than taken from a stored column, so a gateway that dies cannot leave a host reading Connected for ever. The other two are the stamp left when no connector has beaten yet, which no heartbeat has had a chance to contradict.
The identity column
Client certificates are issued for 90 days, and the connector renews its own once past two thirds of that life, checking hourly. The Identity column is whether that happened.
| Label | When |
|---|---|
Valid, N days left | More than 28 days remain |
Renewal overdue, N days left | Between 1 and 28 days remain |
Expires today: renewal is overdue | Fewer than 24 hours remain |
Expired: re-run the installer on the host with a new token | The certificate has passed its expiry |
Not recorded | The connector enrolled before Fleet stored certificate expiry. Not a warning |
The three middle labels carry the warning colour; Valid, N days left and
Not recorded do not.
Twenty-eight days is the threshold because renewal is due at 30 days left: below
that, a renewal that should have happened did not, with two days of margin for a
host that was switched off.
Renewal authenticates to the gateway with the current certificate, so a machine
powered off across its expiry has no way back on its own. The installer treats
an expired identity as no identity and enrols again, which needs a fresh token:
open the host, press Get the install command, and re-run the one-liner with
the new --token. A restart cannot fix it, and neither can renewal.
Connector lifecycle covers renewal, self-update and revocation. Remove a host covers taking one out, including the part Fleet cannot do: the connector package stays installed on your machine, because nothing in Fleet can reach into your network to remove it.