Skip to main content

Your own hosts

A host of your own is a machine you run, reached through a connector you install on it, inside your own network. You add the host in Fleet, Fleet mints an enrollment token, you run one command on the machine, and the connector dials out to Fleet and holds the session open. It reports the host and runs the services you allow on it.

Nothing connects into your network at any point, so there is no inbound firewall rule to add, no port to publish and no address to expose. The other kind of row, found in your Wazuh Cloud account, is Wazuh Cloud environments.

Adding one​

Open Hosts and press Add a host, or use the same button on the Overview. Name the host and press Add host. This needs an admin role or the add-hosts permission on your membership; see Team and roles.

The name is yours to choose and the machine name is the useful one, because it is what the table shows beside the hostname the connector reports.

The host exists the moment the API answers, listed as Not connected. Fleet mints a single-use enrollment token, stores only its SHA-256 hash, and shows the one-liner once:

curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<ENROLLMENT_TOKEN>

Run it as root on a Linux machine with systemd. The installer verifies the binary's published checksum, stages the gateway CA, writes /etc/fleet-connector/connector.yaml, enrols, looks once for the Wazuh login the host keeps, and starts the service. It asks nothing and takes no typed credentials of any kind. The login it finds stays on the host, for the services installed there through Fleet. See The Wazuh login the installer finds. Install the connector is the full procedure.

The connector generates its own key pair on the machine, sends a certificate request with the token, and receives a client certificate whose subject carries its connector id, your tenant and this host. The private key never leaves the machine. On its first heartbeat the host becomes Connected, and the page takes you to it.

The token is single use and expires in 60 minutes

It is shown once, only its hash is stored, and the first enrolment that redeems it consumes it. If the hour passes before you reach the machine, open the host and press Get the install command to mint a fresh one. A token enrols one machine: adding a second host means adding it in Fleet, with its own name and its own token.

One host, one connector​

A host in Fleet is one machine running one connector. The enrollment token is single use, and the gateway keeps one live session per host, so a second connector dialling for the same host supersedes the first, whose session is closed.

A distributed Wazuh deployment is therefore not one row. Each machine you want Fleet to reach is its own host, added and installed on its own, and each appears in the table with what it last reported.

A host's page​

See detail, from the table or from a card on the Overview, opens the host's own page.

Information carries its name, its kind and its Fleet id. In Fleet is the link itself: the status, when it was added, the connector's id, and the data path, which reads "Running in your network, dialing the Fleet gateway outbound." The Remove from Fleet control lives there, and Remove a host is what it does.

Host details is what the connector last reported.

FieldWhat the host reports
StatusOnline or Offline
Last heartbeatHow long ago it checked in, or never for a connector that enrolled and has not beaten yet
PlatformThe operating system and architecture, for example Ubuntu 24.04 LTS · linux/amd64
ConnectorThe connector version it is running, or unknown
HostnameThe name the machine reports for itself
IdentityThe client certificate's remaining life, described below

Before any connector has enrolled the card says so plainly: No connector has enrolled for this host yet. Run the installer on the machine; it appears here on its first heartbeat. A read that fails renders no fields at all, only a sentence naming the layer that refused: an empty card and one that could not be loaded look identical, and only one means the connector never reported.

Under those fields, the services enabled on the host are listed, each with its own state. A service that is not healthy says why in its own words, and one whose status Fleet cannot read at all reads as unknown rather than bad. Fleet reports whether a service's process is alive and enrolled on that machine. Whether the product itself is working is that product's own console. See Other Wazuh products on your hosts.

Online means a heartbeat inside 90 seconds​

The connector heartbeats every 30 seconds by default, configurable as heartbeat_seconds in /etc/fleet-connector/connector.yaml. Fleet reads a host as Online while its last heartbeat is younger than 90 seconds, three beats at that default. The API sends that window with the rows and the page re-derives Online against the browser's clock, so a page left open ages instead of freezing on the answer it was given when it loaded.

Two other timers sit around that one. The gateway drops a session that has sent nothing for 75 seconds, deliberately below the 90, so the sessions the gateway believes in are always a subset of what the console shows as connected. The connector's own watchdog ends a session when three heartbeat intervals pass with no acknowledgement, and redials.

A host that stops reporting keeps its row. The dot goes grey, the status reads Offline and the last heartbeat ages, while every other field still shows what the final heartbeat said: history rather than the present, and the timestamp beside the status is what tells you which. The host's own status follows the same window:

StatusWhat it means
Not connectedThe host exists in Fleet and no connector has enrolled for it
ConnectingA connector redeemed the token and has not sent a heartbeat yet
ConnectedA heartbeat arrived within the last 90 seconds
DisconnectedA connector has beaten before and none has beaten within the window

Connected and Disconnected are worked out from the connector rows on every read rather than taken from a stored column, so a gateway that dies cannot leave a host reading Connected for ever. The other two are the stamp left when no connector has beaten yet, which no heartbeat has had a chance to contradict.

The identity column​

Client certificates are issued for 90 days, and the connector renews its own once past two thirds of that life, checking hourly. The Identity column is whether that happened.

LabelWhen
Valid, N days leftMore than 28 days remain
Renewal overdue, N days leftBetween 1 and 28 days remain
Expires today: renewal is overdueFewer than 24 hours remain
Expired: re-run the installer on the host with a new tokenThe certificate has passed its expiry
Not recordedThe connector enrolled before Fleet stored certificate expiry. Not a warning

The three middle labels carry the warning colour; Valid, N days left and Not recorded do not. Twenty-eight days is the threshold because renewal is due at 30 days left: below that, a renewal that should have happened did not, with two days of margin for a host that was switched off.

An expired certificate cannot renew itself

Renewal authenticates to the gateway with the current certificate, so a machine powered off across its expiry has no way back on its own. The installer treats an expired identity as no identity and enrols again, which needs a fresh token: open the host, press Get the install command, and re-run the one-liner with the new --token. A restart cannot fix it, and neither can renewal.

Connector lifecycle covers renewal, self-update and revocation. Remove a host covers taking one out, including the part Fleet cannot do: the connector package stays installed on your machine, because nothing in Fleet can reach into your network to remove it.