Skip to main content

Add your first host

Fleet's console is empty until a host is added to it. There are two kinds of row and they arrive in completely different ways, so start by deciding which one you have. Nothing has to be linked first: a Wazuh Cloud account is optional, and the console opens on an empty fleet without one. If you have neither yet, the playground is the same console over fictitious data and needs no account.

Two kinds, added differently​

KindHow it is addedWhen it appears in Fleet
A host of your ownYou add it in the console, then run a one-line installer on the machine inside your network. The connector dials out and holds the session open.On the connector's first heartbeat
Wazuh Cloud (SaaS)Fleet pairs with your Wazuh Cloud account and lists the environments it finds there as detected. Connect to Fleet on one asks Wazuh Cloud to deploy a Fleet connector inside it.Once connected, on the connector's first heartbeat

The rest of this page is the first path. The Wazuh Cloud half is described at the end of this page.

Before you start​

  • You are signed in with Wazuh ID, and you may add hosts: admins always may, and a member may when an admin has ticked can add new hosts for them on the Team page. Without it the API answers 403 and the console says you do not have permission to add hosts in this workspace.
  • A Linux machine with systemd, x86_64 or aarch64, that you can run commands on as root, with curl or wget available. It does not have to be a Wazuh server. The installer refuses any other architecture and any machine with no systemctl.
  • Outbound HTTPS on 443 from that machine to dl.fleet.wazuh.com for the download and connect.fleet.wazuh.com for the session. No inbound port is opened. The standard HTTPS_PROXY variables are honoured.

Where a first sign-in lands​

Signing in opens /wazuh/overview, the fleet overview. That is Fleet's front door, so nothing stands between the session resolving and the console. Wazuh Cloud pairing is read only to decide what to offer you, and it is never a gate.

With nothing registered yet, the Overview reads No hosts yet. and offers Add your first host. That button is where Step 1 below starts.

Until a Wazuh Cloud account is linked, a Connect Wazuh Cloud banner sits at the top of Fleet's own screens, the ones carrying Overview, Hosts, Team and Help: "Import the environments from your Wazuh Cloud account. Optional: you can add your own hosts without it." Its button opens the linking flow at /wazuh. Leaving it alone blocks nothing on this page. For an account that is already linked, the notice in that spot is the temporary bridge one instead, about Wazuh Cloud and Wazuh ID still being two logins; that one is dismissible and stays dismissed for the browser you dismissed it in. If the pairing status cannot be read at all, neither notice appears and the console renders regardless, rather than reporting an account as unlinked when the truth is that Fleet could not ask.

Step 1. Add the host​

Open Hosts and press Add a host, or use the same button on the Overview. Name the host, using the machine's own name if you have nothing better, and press Add host.

The row exists the moment the API answers, listed as Not connected. The response also carries a single-use enrollment token, valid for 60 minutes, and the one-line command that carries it. Copy the command.

The token is shown once, and it enrols one machine

If the 60 minutes pass before you run the command, open the host and press Get the install command, which mints a fresh token for it. A host that is already connected has Re-enroll this host in the same place, which does the same thing for a machine that needs a new identity. A token enrols one machine: a second machine is a second host, added on its own. On a machine that already has a connector the command stops without changing anything, so use Re-enroll this host for it instead.

Step 2. Run the command on the machine​

curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<ENROLLMENT_TOKEN>

That is the whole command. It passes no other flags, so the binary's compiled defaults are the shipped install: it dials wss://connect.fleet.wazuh.com and keeps its state in /var/lib/fleet-connector.

The installer works locally and outbound only. In order, it does seven things.

  1. It requires root and systemd, and detects the architecture.
  2. It downloads the static fleet-connector binary for this architecture and refuses to install it unless the published .sha256 matches. A checksum that is not published, or that cannot be fetched, is a refusal too. --allow-unverified is the only way past either, and it is logged as a warning rather than as a verification.
  3. It fetches the gateway CA to /var/lib/fleet-connector/ca.pem, which is what the connector trusts for the enrolment call, rather than the system trust store.
  4. It writes /etc/fleet-connector/connector.yaml with mode 0600: the gateway, the data directory and how often to report. It detects nothing, asks for nothing and takes no credentials, and nothing written into that file ever leaves the machine.
  5. It enrols once with the token, which issues the connector's mTLS identity.
  6. It looks, once, for the Wazuh login the host keeps, reading files only, and keeps it on the host for the services installed there through Fleet. --no-discover skips it. See The Wazuh login the installer finds.
  7. It installs and restarts fleet-connector.service.

The one-line command takes the enrollment token and nothing else. Fleet holds no Wazuh credential, so the installer does not ask for one and refuses any passed to it. A service installed on the host later starts with the login the installer found, when it found one, and a login set from that product's own console replaces it. See connector configuration and Install the connector for the per-host detail.

The last line the installer prints is:

[fleet] done: 'systemctl status fleet-connector' to check, journalctl -u fleet-connector for logs

Step 3. Wait for it to come Connected​

The connector sends a heartbeat every 30 seconds, and the host's status is derived from those heartbeats rather than stored:

PillWhat it means
Not connectedAdded, and no connector has enrolled for it
ConnectingA connector enrolled and has not sent a heartbeat yet
ConnectedA heartbeat arrived less than 90 seconds ago
DisconnectedA connector has beaten before, but not within the last 90 seconds

So the expected sequence is Not connected, then Connecting within the run, then Connected once the first heartbeat lands. The add page watches for it and takes you to the host when it arrives. Until that first heartbeat, the host's Host details card reads "No connector has enrolled for this host yet. Run the installer on the machine; it appears here on its first heartbeat."

Reload to see the change

The host's page does not poll. It reads once when it mounts, so a status that changed on the server appears after a reload rather than on its own.

The first sign of success in Fleet is the Host details card filling in. It carries the status, the last heartbeat, the platform, the connector version, the hostname the machine reports for itself, and the identity certificate's remaining life. Under those fields the services installed on the host are listed, and one that is degraded says why in its own words.

Step 4. Open it​

Open Hosts in the sidebar and select See detail on the host's row. Its detail page opens at /wazuh/environments/detail/?id=<id> and shows what the host is, its connector, the services on it, and where Fleet stands with it.

That is the whole reward for the install: the host is in the Hosts table, with no inbound port opened and nobody logging into the machine again. What Fleet can and cannot do with a host is set out in What Fleet can do.

Three things are worth doing next:

  • Connector configuration for every field a host owner may set and which keys from an older file are ignored. Connector lifecycle is what the host does from now on without being asked: heartbeats, staged self-updates, certificate renewal, and how access ends.
  • Team and access to invite the rest of your organization and decide who may open which host. A grant is enforced on every request, not only hidden from a list.
  • Other Wazuh products on your hosts if one of them should also run on the machines this connector already runs on. Wazuh Vesper, Wazuh Mobius and Wazuh Pharos each ship a Fleet plugin, and each one's download host and enrolment endpoint are compiled into the connector binary you installed rather than taken from the wire.

Wazuh Cloud environments are detected, then connected​

If your Wazuh ID email is verified and matches a Wazuh Cloud account, Fleet pairs with it on its own and lists that account's environments under Detected in Wazuh Cloud. Nothing waits on that: an unpaired account gets the whole console and the Connect Wazuh Cloud banner, whose button is the way into the linking flow. The alternative, pairing by a code sent to a Wazuh Cloud address, does not work today: Fleet's email delivery is not set up, so that request answers "We cannot send the connection code yet because email delivery is not set up. Please contact us."

Detected means Fleet found the environment in your Wazuh Cloud account and no connector is deployed for it. It is not managed in Fleet, and everything shown for it comes from your Wazuh Cloud account rather than from the environment itself. You can still open each one in Wazuh Cloud from its card.

Every detected card Wazuh Cloud has not terminated carries a Connect to Fleet button. Pressing it asks Wazuh Cloud to deploy a Fleet connector inside the environment, and the card moves to Hosts in Fleet as Connecting. There is no installer to run and no machine to prepare: Wazuh Cloud deploys and updates that connector. It reads Connected on the connector's first heartbeat, a few minutes later, and from then on it sits in the Hosts table like any other host. See Wazuh Cloud environments.

If it does not come up​

  • enrolment failed (token expired or already used? mint a new one). The 60 minutes passed, or that token was already consumed. Mint another from the host's page.
  • a Fleet connector is already installed on this host. The machine already has a connector, and nothing was changed. To give it a new identity, or to move it to a different host in Fleet, re-run with --re-enroll --token=…. See Re-installing on a host that already has a connector.
  • no checksum is published for this binary; refusing to install it unverified. The .sha256 beside the binary could not be fetched. Check that nothing between the machine and dl.fleet.wazuh.com rewrites responses.
  • Nothing reaches the gateway. Confirm outbound :443 to connect.fleet.wazuh.com, and HTTPS_PROXY if egress is proxied.

More on the machine's side is in the connector and Connector lifecycle; more on the Fleet side in Your own hosts.