The Hosts page
Hosts is the second entry in Fleet's left sidebar, under Overview, and it lists every machine running a Fleet connector. A host appears there on its first heartbeat, whatever else runs on it. The hosts Wazuh Cloud runs for the environments you have connected are in the same table, because a host is a host wherever it runs.
The table
One row per host, sorted with the reachable ones first.
| Column | What it shows |
|---|---|
| Host | The name the host was registered under, with its hostname under it when the two differ |
| Platform | The operating system and architecture the connector reported, for example Ubuntu 24.04 LTS · linux/amd64. A host Wazuh Cloud runs reads Wazuh Cloud · linux/amd64 |
| Connector | The connector version, and when it last checked in |
| Identity | The remaining life of the client certificate, described in Your own hosts |
| Services | One line per service installed on the host, each with its own state, or None |
| See detail, the way into that host's own page |
The search box above the table filters on the two names, and both the search and the page you are on live in the address bar, so a filtered view is a link you can send to somebody. The table pages at five rows and keeps one row height across pages, so the pager does not walk up the screen as you move through it. A new search goes back to the first page.
An empty table and one that could not be loaded look identical, so they never read the same. With no hosts at all the page says "No hosts yet" and offers Add a host. With a search that matches none of them it says so and gives the total. A read that failed shows the sentence naming the layer that refused, and no table.
The Overview
Overview, the entry above it, answers how the fleet is doing rather than listing it.
Two tiles count what is reachable right now, Wazuh Cloud hosts and On-prem hosts. Beside them, Hosts by status is a chart of the whole fleet with a legend carrying each slice's count and share. Every tile is absent rather than zero when the read behind it did not answer: a zero under a banner is still a zero, and the three reads are independent, so a failed Wazuh Cloud read keeps the rest of the page.
Below that, Hosts in Fleet holds a card per host, each with See detail and a Remove control, and Detected in Wazuh Cloud holds the rest of your Wazuh Cloud account.
Detected is not in Fleet
A detected environment is one Fleet found in your Wazuh Cloud account with no connector deployed for it. It is not managed in Fleet, no service can be enabled on it, and everything shown for it comes from your Wazuh Cloud account rather than from the environment itself. The console states this above the grid, in the same words it uses in the Connect dialog.
The notice you get after removing a Wazuh Cloud environment says the same thing in its own words, because it is telling you what has happened rather than what a section contains.
An environment cannot appear twice. The detected grid is filtered against Fleet's own registry by the environment's Wazuh Cloud id, so connecting one moves its card up, and removing it puts it back.
Two status vocabularies, side by side
The pill on a card is drawn by one function that knows two vocabularies. One describes a Wazuh Cloud environment. The other describes whether Fleet can reach a host.
| Pill | Vocabulary | Raw status | What it answers |
|---|---|---|---|
| Active | Wazuh Cloud | ready | Wazuh Cloud considers the environment up |
| Deploying | Wazuh Cloud | deploying | It is being built or changed |
| Terminated | Wazuh Cloud | terminated | Wazuh Cloud has ended it |
| Connected | Fleet | connected | A connector for it beat within the last 90 seconds |
| Connecting | Fleet | connecting | A connector enrolled and has not beaten yet |
| Not connected | Fleet | detected | It is in Fleet's registry and no connector has enrolled |
| Disconnected | Fleet | disconnected | A connector has beaten before, but not inside the window |
| Error | Fleet | error | The control plane recorded a failure |
| Unknown | neither | empty | Nothing reported a status at all |
| the status as it came | neither | anything unmatched | Fleet does not recognise the status and does not guess at it |
Fleet's own set is closed, so it is matched exactly and first. Wazuh Cloud's is
the upstream's and keeps growing, so it is matched on fragments of the word: a
status containing ready, deploy, terminat or cancel lands on the pill
above without Fleet having to know every string Wazuh Cloud can send. The three
raw values in the table are the ones attested in Fleet's own code and tests;
other Wazuh Cloud statuses reach the same pills through those fragments.
Connected and Active answer different questions, which is why they are two words and not one. Active is Wazuh Cloud's opinion of the environment. Connected is Fleet's report of the link to it, and a detected environment can be perfectly Active while Fleet has no connector reaching it at all. A status Fleet does not recognise is rendered as it came, in neutral grey, rather than guessed at.
The Overview's chart groups on what those pills mean rather than on the raw word, which is what lets one chart carry both vocabularies: Connected, Deploying, Not reachable, Terminated and Unknown. A slice with nothing in it is left out, because a legend entry reading zero is a category somebody then goes looking for.
Connected is derived when the page is read, not stored: a heartbeat younger than 90 seconds, which is three missed 30 second beats, reads Connected; a connector that has beaten before but not inside that window reads Disconnected; a connector that enrolled and has never beaten leaves Connecting; no connector at all leaves the registry's own word.
detected is in both vocabularies and means two different thingsA host that has just been registered is stored with the status detected, and
its pill reads Not connected. That is Fleet saying "in your list, no
connector yet". It is not the Detected in Wazuh Cloud grid, which is about
environments that are not in Fleet at all. Run the installer and the pill goes
Connecting, then Connected. See Your own hosts and
Install the connector.
Terminated environments are listed forever
Your Wazuh Cloud account list is a history, not an inventory. A cancelled
subscription or an expired trial keeps coming back with status: terminated and
a termination date, so it keeps a card in the detected grid with a Terminated
pill. In place of a Connect control, that card names the termination date and
then carries its reason: "Wazuh Cloud keeps terminated environments in your
account history, so it stays listed here, but it cannot be connected or opened."
It gets no XDR button either: where that button would be, the card reads "No XDR
UI to open."
Terminated and ready are not opposites. A deploying environment is neither, so the two controls are decided separately: it still gets the Connect control, and in place of the XDR button it reads "XDR UI available once ready."
Pressing Connect to Fleet on a detected card asks Wazuh Cloud to deploy a Fleet connector inside that environment. The card moves to Hosts in Fleet as Connecting and reads Connected on the connector's first heartbeat, a few minutes later. The sentence above the grid says so: "Fleet asks Wazuh Cloud to deploy a Fleet connector inside this environment. It takes a few minutes; the environment goes Connected on the connector's first heartbeat." See Wazuh Cloud environments.
An empty list is not an inventory
An empty Detected in Wazuh Cloud grid has four causes, and only one of them is "you have connected everything":
- your Wazuh Cloud account has no other environments,
- every environment it has is already in Fleet, and was de-duplicated out,
- your Fleet organization is not paired to a Wazuh Cloud account at all, so there is nothing to detect, or
- the read failed.
Only the last one is signalled, and deliberately so: a failed read shows an amber banner, and the sentence in it depends on which layer failed. An expired session, a refused Wazuh Cloud account and an upstream that did not answer each get their own wording; anything else falls back to "Your Wazuh Cloud environments could not be listed. This is not the same as having none." The registry read has the same fallback in its own words. If the registry read is the one that failed, the detected grid is withheld entirely rather than shown without its de-duplication, which would offer a Connect button for environments you already have.
When both reads answered and there is nothing at all, the Overview says "No hosts yet." and offers Add your first host. An organization with no Wazuh Cloud account linked reaches both pages like any other, and once Fleet has read its pairing status and found none, a Connect Wazuh Cloud offer sits at the top of both. See Wazuh Cloud environments.