Skip to main content

The Hosts page

Hosts is the second entry in Fleet's left sidebar, under Overview, and it lists every machine running a Fleet connector. A host appears there on its first heartbeat, whatever else runs on it. The hosts Wazuh Cloud runs for the environments you have connected are in the same table, because a host is a host wherever it runs.

The table​

One row per host, sorted with the reachable ones first.

ColumnWhat it shows
HostThe name the host was registered under, with its hostname under it when the two differ
PlatformThe operating system and architecture the connector reported, for example Ubuntu 24.04 LTS · linux/amd64. A host Wazuh Cloud runs reads Wazuh Cloud · linux/amd64
ConnectorThe connector version, and when it last checked in
IdentityThe remaining life of the client certificate, described in Your own hosts
ServicesOne line per service installed on the host, each with its own state, or None
See detail, the way into that host's own page

The search box above the table filters on the two names, and both the search and the page you are on live in the address bar, so a filtered view is a link you can send to somebody. The table pages at five rows and keeps one row height across pages, so the pager does not walk up the screen as you move through it. A new search goes back to the first page.

An empty table and one that could not be loaded look identical, so they never read the same. With no hosts at all the page says "No hosts yet" and offers Add a host. With a search that matches none of them it says so and gives the total. A read that failed shows the sentence naming the layer that refused, and no table.

The Overview​

Overview, the entry above it, answers how the fleet is doing rather than listing it.

Two tiles count what is reachable right now, Wazuh Cloud hosts and On-prem hosts. Beside them, Hosts by status is a chart of the whole fleet with a legend carrying each slice's count and share. Every tile is absent rather than zero when the read behind it did not answer: a zero under a banner is still a zero, and the three reads are independent, so a failed Wazuh Cloud read keeps the rest of the page.

Below that, Hosts in Fleet holds a card per host, each with See detail and a Remove control, and Detected in Wazuh Cloud holds the rest of your Wazuh Cloud account.

Detected is not in Fleet​

A detected environment is one Fleet found in your Wazuh Cloud account with no connector deployed for it. It is not managed in Fleet, no service can be enabled on it, and everything shown for it comes from your Wazuh Cloud account rather than from the environment itself. The console states this above the grid, in the same words it uses in the Connect dialog.

The notice you get after removing a Wazuh Cloud environment says the same thing in its own words, because it is telling you what has happened rather than what a section contains.

An environment cannot appear twice. The detected grid is filtered against Fleet's own registry by the environment's Wazuh Cloud id, so connecting one moves its card up, and removing it puts it back.

Two status vocabularies, side by side​

The pill on a card is drawn by one function that knows two vocabularies. One describes a Wazuh Cloud environment. The other describes whether Fleet can reach a host.

PillVocabularyRaw statusWhat it answers
ActiveWazuh CloudreadyWazuh Cloud considers the environment up
DeployingWazuh ClouddeployingIt is being built or changed
TerminatedWazuh CloudterminatedWazuh Cloud has ended it
ConnectedFleetconnectedA connector for it beat within the last 90 seconds
ConnectingFleetconnectingA connector enrolled and has not beaten yet
Not connectedFleetdetectedIt is in Fleet's registry and no connector has enrolled
DisconnectedFleetdisconnectedA connector has beaten before, but not inside the window
ErrorFleeterrorThe control plane recorded a failure
UnknownneitheremptyNothing reported a status at all
the status as it cameneitheranything unmatchedFleet does not recognise the status and does not guess at it

Fleet's own set is closed, so it is matched exactly and first. Wazuh Cloud's is the upstream's and keeps growing, so it is matched on fragments of the word: a status containing ready, deploy, terminat or cancel lands on the pill above without Fleet having to know every string Wazuh Cloud can send. The three raw values in the table are the ones attested in Fleet's own code and tests; other Wazuh Cloud statuses reach the same pills through those fragments.

Connected and Active answer different questions, which is why they are two words and not one. Active is Wazuh Cloud's opinion of the environment. Connected is Fleet's report of the link to it, and a detected environment can be perfectly Active while Fleet has no connector reaching it at all. A status Fleet does not recognise is rendered as it came, in neutral grey, rather than guessed at.

The Overview's chart groups on what those pills mean rather than on the raw word, which is what lets one chart carry both vocabularies: Connected, Deploying, Not reachable, Terminated and Unknown. A slice with nothing in it is left out, because a legend entry reading zero is a category somebody then goes looking for.

Connected is derived when the page is read, not stored: a heartbeat younger than 90 seconds, which is three missed 30 second beats, reads Connected; a connector that has beaten before but not inside that window reads Disconnected; a connector that enrolled and has never beaten leaves Connecting; no connector at all leaves the registry's own word.

detected is in both vocabularies and means two different things

A host that has just been registered is stored with the status detected, and its pill reads Not connected. That is Fleet saying "in your list, no connector yet". It is not the Detected in Wazuh Cloud grid, which is about environments that are not in Fleet at all. Run the installer and the pill goes Connecting, then Connected. See Your own hosts and Install the connector.

Terminated environments are listed forever​

Your Wazuh Cloud account list is a history, not an inventory. A cancelled subscription or an expired trial keeps coming back with status: terminated and a termination date, so it keeps a card in the detected grid with a Terminated pill. In place of a Connect control, that card names the termination date and then carries its reason: "Wazuh Cloud keeps terminated environments in your account history, so it stays listed here, but it cannot be connected or opened." It gets no XDR button either: where that button would be, the card reads "No XDR UI to open."

Terminated and ready are not opposites. A deploying environment is neither, so the two controls are decided separately: it still gets the Connect control, and in place of the XDR button it reads "XDR UI available once ready."

Pressing Connect to Fleet on a detected card asks Wazuh Cloud to deploy a Fleet connector inside that environment. The card moves to Hosts in Fleet as Connecting and reads Connected on the connector's first heartbeat, a few minutes later. The sentence above the grid says so: "Fleet asks Wazuh Cloud to deploy a Fleet connector inside this environment. It takes a few minutes; the environment goes Connected on the connector's first heartbeat." See Wazuh Cloud environments.

An empty list is not an inventory​

An empty Detected in Wazuh Cloud grid has four causes, and only one of them is "you have connected everything":

  • your Wazuh Cloud account has no other environments,
  • every environment it has is already in Fleet, and was de-duplicated out,
  • your Fleet organization is not paired to a Wazuh Cloud account at all, so there is nothing to detect, or
  • the read failed.

Only the last one is signalled, and deliberately so: a failed read shows an amber banner, and the sentence in it depends on which layer failed. An expired session, a refused Wazuh Cloud account and an upstream that did not answer each get their own wording; anything else falls back to "Your Wazuh Cloud environments could not be listed. This is not the same as having none." The registry read has the same fallback in its own words. If the registry read is the one that failed, the detected grid is withheld entirely rather than shown without its de-duplication, which would offer a Connect button for environments you already have.

When both reads answered and there is nothing at all, the Overview says "No hosts yet." and offers Add your first host. An organization with no Wazuh Cloud account linked reaches both pages like any other, and once Fleet has read its pairing status and found none, a Connect Wazuh Cloud offer sits at the top of both. See Wazuh Cloud environments.