Add your first host
Fleet's console is empty until a host is added to it. There are two kinds of row and they arrive in completely different ways, so start by deciding which one you have. Nothing has to be linked first: a Wazuh Cloud account is optional, and the console opens on an empty fleet without one. If you have neither yet, the playground is the same console over fictitious data and needs no account.
Two kinds, added differently
| Kind | How it is added | When it appears in Fleet |
|---|---|---|
| A host of your own | You add it in the console, then run a one-line installer on the machine inside your network. The connector dials out and holds the session open. | On the connector's first heartbeat |
| Wazuh Cloud (SaaS) | Fleet pairs with your Wazuh Cloud account and lists the environments it finds there as detected. Connect to Fleet on one asks Wazuh Cloud to deploy a Fleet connector inside it. | Once connected, on the connector's first heartbeat |
The rest of this page is the first path. The Wazuh Cloud half is described at the end of this page.
Before you start
- You are signed in with Wazuh ID, and you may add
hosts: admins always may, and a member may when an admin has ticked
can add new hosts for them on the Team page. Without
it the API answers
403and the console says you do not have permission to add hosts in this workspace. - A Linux machine with systemd,
x86_64oraarch64, that you can run commands on as root, withcurlorwgetavailable. It does not have to be a Wazuh server. The installer refuses any other architecture and any machine with nosystemctl. - Outbound HTTPS on 443 from that machine to
dl.fleet.wazuh.comfor the download andconnect.fleet.wazuh.comfor the session. No inbound port is opened. The standardHTTPS_PROXYvariables are honoured.
Where a first sign-in lands
Signing in opens /wazuh/overview, the fleet overview. That is Fleet's front
door, so nothing stands
between the session resolving and the console. Wazuh Cloud pairing is read only
to decide what to offer you, and it is never a gate.
With nothing registered yet, the Overview reads No hosts yet. and offers Add your first host. That button is where Step 1 below starts.
Until a Wazuh Cloud account is linked, a Connect Wazuh Cloud banner sits at
the top of Fleet's own screens, the ones carrying Overview, Hosts, Team and
Help: "Import the environments from your Wazuh Cloud account. Optional: you can
add your own hosts without it." Its button opens the linking flow at /wazuh.
Leaving it alone blocks nothing on this page. For an account that is already
linked, the notice in that spot is the temporary bridge one instead, about
Wazuh Cloud and Wazuh ID still being two logins; that one is dismissible and
stays dismissed for the browser you dismissed it in. If the pairing status
cannot be read at all, neither notice appears and the console renders
regardless, rather than reporting an account as unlinked when the truth is that
Fleet could not ask.
Step 1. Add the host
Open Hosts and press Add a host, or use the same button on the Overview. Name the host, using the machine's own name if you have nothing better, and press Add host.
The row exists the moment the API answers, listed as Not connected. The response also carries a single-use enrollment token, valid for 60 minutes, and the one-line command that carries it. Copy the command.
If the 60 minutes pass before you run the command, open the host and press Get the install command, which mints a fresh token for it. A host that is already connected has Re-enroll this host in the same place, which does the same thing for a machine that needs a new identity. A token enrols one machine: a second machine is a second host, added on its own. On a machine that already has a connector the command stops without changing anything, so use Re-enroll this host for it instead.
Step 2. Run the command on the machine
curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<ENROLLMENT_TOKEN>
That is the whole command. It passes no other flags, so the binary's compiled
defaults are the shipped install: it dials wss://connect.fleet.wazuh.com and
keeps its state in /var/lib/fleet-connector.
The installer works locally and outbound only. In order, it does seven things.
- It requires root and systemd, and detects the architecture.
- It downloads the static
fleet-connectorbinary for this architecture and refuses to install it unless the published.sha256matches. A checksum that is not published, or that cannot be fetched, is a refusal too.--allow-unverifiedis the only way past either, and it is logged as a warning rather than as a verification. - It fetches the gateway CA to
/var/lib/fleet-connector/ca.pem, which is what the connector trusts for the enrolment call, rather than the system trust store. - It writes
/etc/fleet-connector/connector.yamlwith mode0600: the gateway, the data directory and how often to report. It detects nothing, asks for nothing and takes no credentials, and nothing written into that file ever leaves the machine. - It enrols once with the token, which issues the connector's mTLS identity.
- It looks, once, for the Wazuh login the host keeps, reading files only, and
keeps it on the host for the services installed there through Fleet.
--no-discoverskips it. See The Wazuh login the installer finds. - It installs and restarts
fleet-connector.service.
The one-line command takes the enrollment token and nothing else. Fleet holds no Wazuh credential, so the installer does not ask for one and refuses any passed to it. A service installed on the host later starts with the login the installer found, when it found one, and a login set from that product's own console replaces it. See connector configuration and Install the connector for the per-host detail.
The last line the installer prints is:
[fleet] done: 'systemctl status fleet-connector' to check, journalctl -u fleet-connector for logs
Step 3. Wait for it to come Connected
The connector sends a heartbeat every 30 seconds, and the host's status is derived from those heartbeats rather than stored:
| Pill | What it means |
|---|---|
| Not connected | Added, and no connector has enrolled for it |
| Connecting | A connector enrolled and has not sent a heartbeat yet |
| Connected | A heartbeat arrived less than 90 seconds ago |
| Disconnected | A connector has beaten before, but not within the last 90 seconds |
So the expected sequence is Not connected, then Connecting within the run, then Connected once the first heartbeat lands. The add page watches for it and takes you to the host when it arrives. Until that first heartbeat, the host's Host details card reads "No connector has enrolled for this host yet. Run the installer on the machine; it appears here on its first heartbeat."
The host's page does not poll. It reads once when it mounts, so a status that changed on the server appears after a reload rather than on its own.
The first sign of success in Fleet is the Host details card filling in. It carries the status, the last heartbeat, the platform, the connector version, the hostname the machine reports for itself, and the identity certificate's remaining life. Under those fields the services installed on the host are listed, and one that is degraded says why in its own words.
Step 4. Open it
Open Hosts in the sidebar and select See detail on the host's row. Its
detail page opens at /wazuh/environments/detail/?id=<id> and shows what the
host is, its connector, the services on it, and where Fleet stands with it.
That is the whole reward for the install: the host is in the Hosts table, with no inbound port opened and nobody logging into the machine again. What Fleet can and cannot do with a host is set out in What Fleet can do.
Three things are worth doing next:
- Connector configuration for every field a host owner may set and which keys from an older file are ignored. Connector lifecycle is what the host does from now on without being asked: heartbeats, staged self-updates, certificate renewal, and how access ends.
- Team and access to invite the rest of your organization and decide who may open which host. A grant is enforced on every request, not only hidden from a list.
- Other Wazuh products on your hosts if one of them should also run on the machines this connector already runs on. Wazuh Vesper, Wazuh Mobius and Wazuh Pharos each ship a Fleet plugin, and each one's download host and enrolment endpoint are compiled into the connector binary you installed rather than taken from the wire.
Wazuh Cloud environments are detected, then connected
If your Wazuh ID email is verified and matches a Wazuh Cloud account, Fleet pairs with it on its own and lists that account's environments under Detected in Wazuh Cloud. Nothing waits on that: an unpaired account gets the whole console and the Connect Wazuh Cloud banner, whose button is the way into the linking flow. The alternative, pairing by a code sent to a Wazuh Cloud address, does not work today: Fleet's email delivery is not set up, so that request answers "We cannot send the connection code yet because email delivery is not set up. Please contact us."
Detected means Fleet found the environment in your Wazuh Cloud account and no connector is deployed for it. It is not managed in Fleet, and everything shown for it comes from your Wazuh Cloud account rather than from the environment itself. You can still open each one in Wazuh Cloud from its card.
Every detected card Wazuh Cloud has not terminated carries a Connect to Fleet button. Pressing it asks Wazuh Cloud to deploy a Fleet connector inside the environment, and the card moves to Hosts in Fleet as Connecting. There is no installer to run and no machine to prepare: Wazuh Cloud deploys and updates that connector. It reads Connected on the connector's first heartbeat, a few minutes later, and from then on it sits in the Hosts table like any other host. See Wazuh Cloud environments.
If it does not come up
enrolment failed (token expired or already used? mint a new one). The 60 minutes passed, or that token was already consumed. Mint another from the host's page.a Fleet connector is already installed on this host. The machine already has a connector, and nothing was changed. To give it a new identity, or to move it to a different host in Fleet, re-run with--re-enroll --token=…. See Re-installing on a host that already has a connector.no checksum is published for this binary; refusing to install it unverified. The.sha256beside the binary could not be fetched. Check that nothing between the machine anddl.fleet.wazuh.comrewrites responses.- Nothing reaches the gateway. Confirm outbound
:443toconnect.fleet.wazuh.com, andHTTPS_PROXYif egress is proxied.
More on the machine's side is in the connector and Connector lifecycle; more on the Fleet side in Your own hosts.