Wazuh Cloud environments
Fleet can read a Wazuh Cloud (SaaS) account and list the environments in it beside the hosts you run yourself. That listing is a different thing from an environment being in Fleet: pairing an account tells Fleet what you have, while a connector is what puts one in your fleet. For a Wazuh Cloud environment the connector is deployed by Wazuh Cloud itself, on request from Fleet, and everything below says which side of that line each control is on.
Pairing is optional and nothing in Fleet waits on it. The front door is the
fleet overview at /wazuh/overview, which opens as soon as your session
resolves, whether or not a Wazuh Cloud account is linked, and you can
add a host of your own behind a connector without
ever pairing one. An empty fleet on that overview offers both routes rather than
one: a machine of yours with a connector, or a Wazuh Cloud account to import
environments from. Skipping the pairing costs you the detected list described
below, and nothing else: no environment appears on its own, so you add each
deployment yourself. What a pairing changes is what Fleet offers at the top of
the page and in the profile menu, not what any screen will let you do.
Pairing an account
The pairing is per tenant and it is proved by email control, never by an id you
type. The flow lives at /wazuh and is reached from the Connect Wazuh Cloud
banner, which sits at the top of every Fleet page until an account is linked
(except the connect page itself, which is where it leads) and says the same thing
this page does: that hosts of your own do not need it. Nothing sends you there
on its own, and the banner is absent while Fleet has not been able to read your
pairing status, because not being able to ask is not the same answer as not being
paired.
There are two ways the pairing happens.
Automatic. If the email on your Wazuh ID is verified and Wazuh Cloud has an account for that same address, Fleet matches the two the first time it reads your pairing status. Nothing is asked and no mail is sent, which is what makes it the only pairing path that works end to end today.
By code. If your Wazuh Cloud account uses a different address, the connect
form at /wazuh says it did not find a Wazuh Cloud account for your Wazuh ID
email, and asks for the other one. Fleet then emails a six digit code to that
address and you paste it back into the form. The code is what proves you control
the mailbox; there is no link to click.
| Property | Value |
|---|---|
| Code | Six digits, typed or pasted into the form |
| Valid for | 10 minutes from the moment it is issued |
| Requests | One per tenant per 45 seconds, otherwise Please wait a moment before requesting another code. |
| Wrong guesses | Five are checked; the next attempt is refused with Too many attempts. Request a new code. and the pending code is dropped |
| Wrong or late code | That code is invalid or has expired. |
Requesting a code for an address that has no Wazuh Cloud account answers exactly
as it does for one that has: a flat success, with no code arriving. That is
deliberate, because a different answer would turn the form into a way of asking
which addresses hold a Wazuh Cloud account. The single exception applies only
once Fleet can send mail at all: an address that does have an account and whose
code then fails to leave the mail service answers 502, which an address with no
account never does.
The connection code is the only mail Fleet itself sends, and Fleet has no
verified sending address yet, so nothing is sent. Rather than reporting a code it
never attempted, POST /api/cloud/connect/request answers 503 with this
detail, which the form shows verbatim under the button:
We cannot send the connection code yet because email delivery is not set up. Please contact us.
The check runs before the account lookup, so the answer is the same for every address. Until that changes, pairing works only where your Wazuh ID email is also your Wazuh Cloud account email. That is not a way of being locked out of Fleet: the console opens without a pairing, and what is missing is the detected list. Team invitations are unaffected: those are sent by Wazuh ID, not by Fleet. See Team.
Disconnect Wazuh Cloud, in the profile menu at the top right, clears the
stored pairing. It is offered only while an account is linked, so it is absent
before a pairing and absent again when Fleet could not read the status at all.
Unlinking lands you back on /wazuh/overview rather than on the connect form,
and it takes nothing else away: your own hosts, their connectors and every
console screen stay as they were. If your Wazuh ID email is itself a Wazuh
Cloud account address, the next status read matches it again on its own.
What a paired account shows
Fleet asks Wazuh Cloud for the account's environments, capping that request at 100, strips the account, customer and profile identifiers out of each one before it reaches the browser, and then subtracts the environments already in Fleet, matched on the Wazuh Cloud id. What is left is the Detected in Wazuh Cloud section on Environments, and the same rows appear in the Overview's environment list carrying a "Detected only" chip. A pairing that names a single environment rather than a whole account resolves that one alone, and the cap does not apply.
Detected has one meaning and the console states it wherever the word appears: Fleet found the environment in your Wazuh Cloud account and no connector is deployed for it. No service can be enabled on it, it is not managed in Fleet, and everything shown for it comes from the Wazuh Cloud account rather than from the environment itself.
Each detected card carries the agent limit, the region and the Wazuh version, plus a status pill from Wazuh Cloud's own vocabulary. Two controls sit in its footer:
- See detail, to the environment's page in Fleet.
- Open Wazuh XDR UI, to the environment's own dashboard in Wazuh Cloud. It renders only when Wazuh Cloud reports the environment ready and there is a dashboard address to open. An environment that is still deploying gets a short reason in that slot instead of a link, because there is nothing to open yet.
The detail page adds what the account reports about the environment: its Wazuh
Cloud status and plan, the creation date, the termination date where there is
one, the region, the platform version Wazuh Cloud reports, labelled Version
(Wazuh Cloud) because it is not the Wazuh version, and the namespace. Below that a Settings card
carries the values Wazuh Cloud returned under the environment's settings: the
agent and EPS limits, the support plan, indexed capacity and retention, archive
retention, storage type, AI reports and environment type. Only the values Wazuh
Cloud actually returned are shown, and a read that failed says so rather than
showing an empty card: Fleet could not read this environment's settings from Wazuh Cloud, so none are shown. An environment that genuinely reports none says
No configurable settings reported for this environment.
See credentials on the same page fetches that environment's Wazuh dashboard login from Wazuh Cloud on demand, and holds it only for as long as the page is open. Fleet stores no Wazuh Cloud credential of yours: the request re-checks that the environment belongs to your paired account before Wazuh Cloud is asked at all.
What "Connect to Fleet" does
The Connect to Fleet button is present on every detected card Wazuh Cloud has not terminated, in the Connect modal and on a detected environment's detail page. Pressing it does two things in order. Fleet issues an enrolment token that lasts one hour, and asks Wazuh Cloud to deploy a Fleet connector inside the environment with that token. Only then is the environment recorded in Fleet, as Connecting, so a refusal from Wazuh Cloud leaves nothing behind.
The sentence beside the control says what to expect: "Fleet asks Wazuh Cloud to deploy a Fleet connector inside this environment. It takes a few minutes; the environment goes Connected on the connector's first heartbeat." On the Overview and in the Connect modal it sits once above the list rather than under each row.
Wazuh Cloud deploys one connector per environment. It dials the Fleet gateway outbound, exactly as a connector of your own does, and the environment reads Connected on its first heartbeat. From then on it is a host in your fleet, with a row in the Hosts table, and services can be enabled on it.
Two refusals are worth knowing. An environment Wazuh Cloud has not moved to the platform version that supports the connector is refused with "Wazuh Cloud cannot deploy the Fleet connector into this environment yet: it is not on the platform version that supports it." A request Wazuh Cloud did not accept at all reads "Wazuh Cloud did not accept the connect request. Try again in a moment." Neither one records the environment in Fleet.
Connect again
A connected Wazuh Cloud environment's detail page shows its Fleet status under In Fleet. While that status is Connecting, Disconnected or Error, the card also offers Connect again, with this sentence: "The enrollment token lasts one hour. If this stays Connecting, or the connector went Disconnected, press Connect again to issue a new one."
Connect again is the same act as the first Connect. Fleet issues a new token, retires the environment's previous connector at once, and asks Wazuh Cloud for the connector again, and Wazuh Cloud replaces the one it had deployed. The Connector card is empty until the new connector's first heartbeat, then shows it. Nothing has to be removed first.
What the detail page shows once connected
A Wazuh Cloud environment in Fleet is read through a connector the account owner did not install, and its detail page says so. In place of the Host details card a machine of yours gets, it shows a Connector card with one row, the connector Wazuh Cloud deployed, and the sentence "Wazuh Cloud deploys and updates this connector inside the environment, and any service enabled here runs with it. It appears here on its first heartbeat." That connector dials the Fleet gateway outbound, exactly as one of yours does, and the row carries the same facts as any other host. See A host's page.
The row's platform cell reads "Wazuh Cloud · linux/amd64": the machine is Wazuh Cloud's, so that is all Fleet says about it.
There is no Updates card, because Wazuh Cloud owns the connector's version.
Services on a Wazuh Cloud environment
Whether the Services panel appears depends on the connector Wazuh Cloud deployed, not on the environment. A connector that reports it can host services gets the same panel a host of yours has, and a service you enable there runs inside that connector: the Connector card says so in its first sentence. A connector that does not report it yet gets one sentence in place of the panel, which is also the answer any install request for that environment receives, from Fleet or from another Wazuh product's console:
This is a Wazuh Cloud environment. The connector Wazuh Cloud deployed for it does not report that it can host services yet, so nothing can be installed through Fleet here.
If the connector list could not be read, the page says it cannot tell whether services are available, rather than that they are not.
Two things differ from a host of your own once the panel is there. Wazuh Vesper is not available on Wazuh Cloud environments, by design rather than for now: Vesper runs commands on a host you administer, and a Wazuh Cloud environment is not one. Its toggle is disabled before you press it, with the reason beside it, and the same request from Vesper's own console is refused with the same sentence:
This is a Wazuh Cloud environment, and Vesper is not available on Wazuh Cloud environments. It needs a host you administer.
And the root shell control that an exec-capable plugin gets on a host you administer is never offered here. Allowing and disallowing any other service works the same way, and disallowing is never refused. See Other Wazuh products on your hosts.
Removal works for both kinds of environment. Removing a Wazuh Cloud one asks Wazuh Cloud to retire the connector it deployed and puts the environment straight back under Detected in Wazuh Cloud, where Connect to Fleet brings it back. See Removing an environment.
An environment Wazuh Cloud reports as terminated is a separate case. Wazuh Cloud keeps terminated environments in the account history, so they stay listed forever, with their termination date and no Connect or Open control at all.
When the detail page cannot tell
An environment's page reads two places that answer different questions: Fleet's own control plane knows whether the environment is in Fleet, and Wazuh Cloud knows what the environment is. A detected environment has only the second and an on-prem one only the first, so the page has to be honest when neither read is conclusive.
| The page's answer | When | What it shows |
|---|---|---|
| In Fleet | Fleet's control plane returned the environment | Its Fleet status, when it was added, its connector, and Remove from Fleet |
| Not in Fleet | The control plane answered 404 and the Wazuh Cloud read succeeded | What detected means, what Connect does, and the Connect to Fleet control, or the terminated notice where Wazuh Cloud has ended the environment |
| Could not tell | Anything else: an expired session, a 5xx, a blocked request | Fleet could not tell whether this environment is connected. Reload to try again. |
The middle row is the one that needs both reads. A 404 on its own is also what Fleet answers to a caller who may not ask at all, so it proves nothing by itself; a successful read from the other side is what shows the caller cleared that gate. Guessing instead would invite you to connect an environment Fleet was already reading, which is a failure rendered as a fact.
The same discipline governs the destructive control: Remove from Fleet is offered only for the first row. An environment Fleet could not confirm is never offered a removal.
Where to go next
- Add your first host for the path that works end to end today: a machine of yours with a connector, described in full under Your own hosts.
- The playground shows both card grids on invented data, with no account and no backend. Its Wazuh XDR links are samples and do not resolve, and the page says so.