What is Fleet
Fleet is a Wazuh product that puts the machines you run behind one console, live at fleet.wazuh.com. Install the Fleet connector on a machine and it appears here as a host. From the same console an admin allows or disallows each Wazuh product on those hosts, and the product installs its own service through the connector already there.
Fleet reads a host's name, its platform and the connector running on it. When the installer runs on a Wazuh node it also looks, once, for the login Wazuh keeps there, and hands it only to the services installed on that host through Fleet. A service disallowed later keeps it while it is stopped, and removing the service takes it away. That login never leaves the host, and a login set from a service replaces it. Fleet stores no security data and holds no Wazuh credentials.
Fleet is open to any Wazuh ID account. There is no access list and nothing to request: signing in sets a workspace up for your organization, and one organization is one workspace, administered by the first person in. Sign in covers membership, roles and the cases where setting a workspace up does not resolve.
The console can also be seen without an account in the playground, a public build running entirely on fictitious data with no backend at all.
A host, a connector, a service
A host is one machine running one Fleet connector. The connector is a single static Go binary installed on it. Fleet lists machines you added yourself and the ones Wazuh Cloud runs for the environments in your account, in one table.
The connector runs on a host inside your own network and dials out over mTLS
to connect.fleet.wazuh.com, keeping that session alive. There is no inbound
port to open and no firewall rule to change. It heartbeats every 30 seconds by
default, and a host not heard from for 90 seconds stops reading as Online. Its
configuration lives in /etc/fleet-connector/connector.yaml on the host, and
Fleet reaches the host only over the session the connector opens.
The services you allow on a host
A service is a Wazuh product installed on a host through the Fleet connector. It runs beside the connector as its own process, under its own account, in its own sandbox, and it reports to that product rather than to Fleet.
Fleet allows a service per host, and the product installs it from its own console. The host installs and starts it on its next heartbeat, and the service enrols itself with its product. Nobody logs into the machine. A grant to open a host is not permission to allow software on it.
| Product | What it does once allowed on a host |
|---|---|
| Wazuh Vesper | An AI support engineer that answers "why did this break" about that deployment, and can apply the fix |
| Wazuh Mobius | An LLM verdict, priority and threat category on that deployment's security events, correlated into incidents |
| Wazuh Pharos | Vulnerability intelligence narrowed to what you actually run, so a watchlist says which of your machines a CVE affects |
Each product owns its own console, its own credentials and its own reading. The service can start with the login the installer found on the host, and asks for whatever other login it needs in its own console. Neither reaches Fleet. Other Wazuh products on your hosts has the detail, and the click that connects a host to one of them lives in that product's own console today.
One console, every host
A host reaches Fleet in one of two ways.
| Kind | How it is added | What it runs |
|---|---|---|
| A machine you run | Install the connector on it. See Your own hosts | The connector you installed |
| Wazuh Cloud (SaaS) | Pair the account: Fleet matches your Wazuh ID email against it, or sends a code to an address on it. Fleet lists the environments it finds, and Connect to Fleet on one asks Wazuh Cloud to deploy a Fleet connector inside it. See Wazuh Cloud environments | A Fleet connector Wazuh Cloud deploys for each connected environment |
A paired Wazuh Cloud environment starts out detected, which is not the same as connected. A detected environment has no connector deployed for it yet, and everything shown for it comes from the Wazuh Cloud account. Connect to Fleet asks Wazuh Cloud to deploy a connector, and it reads Connected on the first heartbeat. Details on Wazuh Cloud environments.
The console shows the ecosystem rail and, beside it, Fleet's own sidebar, where the hosts, the team and the account screens live. Its Overview and Hosts items lead to every host. See detail on a row of the Hosts page opens that host, its connector and the services on it.
A host's id is in the address bar of its page, so a link pasted into a ticket names the machine it was taken from.
What Fleet is not
Fleet does not read your Wazuh, and it cannot change it. The console holds no Wazuh credentials and the connector carries no query path into your deployment. The login the installer finds stays on the host, with the services installed there. Reading a deployment's own data is a job for a service you allow on the host, working with its own credentials and its own read-only discipline, not for Fleet.
Fleet does not administer Wazuh. Restarting a manager or an agent, editing rules or configuration, and managing agents, groups or API users are all outside what Fleet does. Fleet is the console for the hosts and the services on them, and each service decides for itself what it reads and writes on the machine it was allowed onto.
Next: Sign in, then add your first host.