Getting help
Fleet has no ticket form of its own. The Help screen exists to send you to the place that can act: the Wazuh Cloud console, where the Wazuh Cloud team can see your account and your environments there. No Fleet screen opens or sends a support request.
Most of what people take to support, though, has a shorter answer in this documentation. The triage below is worth ten minutes before the handoff.
The Help screen
Help is at /wazuh/support, in the Support group of the Wazuh Cloud
sidebar. The screen carries one control, Get help in Wazuh Cloud, which
opens
console.cloud.wazuh.com/console/help
in a new tab. Its own words are the reason for the handoff: support requests are
handled in the Wazuh Cloud console, where the Wazuh Cloud team can see your
account and environments.
Beside it, Documentation opens Wazuh's Cloud service documentation at documentation.wazuh.com, also in a new tab.
Both entries live on the Wazuh Cloud account surface, and that whole surface
renders only once your session is paired to a Wazuh Cloud account. Until it is,
every route under /wazuh sends you back to the pairing screen and the sidebar
is not drawn, so this Help screen is not reachable if you run hosts of your own
only. The link it carries is unconditional once you can see it: it
points at the Wazuh Cloud console whether or not that console has anything to
say about your environments.
Triage, in order of how often it is the answer
| Symptom | What it usually is | Where it is answered |
|---|---|---|
| A host will not come Connected | No heartbeat inside the last 90 seconds. Check systemctl status fleet-connector and journalctl -u fleet-connector -f on the machine | Install the connector, Connector logs, Your own hosts |
| A host reads Connecting and stays there | A connector redeemed the token and has not sent its first heartbeat yet | Your own hosts |
| Sign-in is refused | Rare, since Fleet admits any signed-in Wazuh ID account. The screen names the reason: a session still naming a workspace you are no longer a member of, or a workspace of your own that cannot be merged into the one your organization already uses. A screen saying your access could not be confirmed means the check itself failed, most often Wazuh Hub not answering, and is the one worth retrying | Sign in |
| An invitation stays pending | Pending means waiting for them to accept. The email comes from Wazuh, not from Fleet | Team and access |
| Another Wazuh product's plugin on a host reads Could not tell or Crash-looping | Fleet answers one question about a plugin, whether that process is alive and enrolled on that host. Whether the product itself is working is that product's own console, and the two disagreeing is a real state | Other services on your hosts |
One case of the invitation row is worth knowing before it is reported as a bug: a person who already has a Fleet workspace of their own is never moved into the one they were invited to, because moving them would leave their own hosts behind. Their invitation stays pending, and their own console says so.
When a read fails
Fleet reads its own control plane, not your deployments, so the reads that can fail are about which hosts you have and whether Fleet can reach each one. A failure does not render as a zero: a count nobody reported is absent, and a service whose status Fleet cannot read shows as unknown rather than as a state.
The failures worth telling apart are a refused session, a host that is not
yours or is not granted to you, and a host whose connector Fleet cannot reach.
The first sends you to Sign in. The second answers the
same 404 Not found as a host that does not exist, which is deliberate, so a
grant a colleague lacks is a Team question. The third is
a machine question: check the connector there, as in the Connected triage above.
Is it Fleet, or is it my machine?
playground.fleet.wazuh.com is the same console with its data layer replaced by fixtures. Open the screen there. If it renders and behaves, the code path is intact and the question is about the host or the read that reaches it. If it is broken there too, the product is broken, and that is worth reporting with the URL.
The playground signs nobody in, holds no API URL and reaches no machine, so it costs nothing to open. See The playground.
Questions about Wazuh rather than about Fleet
Fleet does not read or change your Wazuh deployment. Rules and decoders, agent enrolment, manager configuration and the meaning of a rule level are Wazuh questions, and Wazuh's own documentation at documentation.wazuh.com is where they are answered.
The console holds no Wazuh credential and the connector carries no path into your deployment, so Fleet reads nothing from it and changes nothing on it. What reads or acts on a deployment is a service you allow on the host, with the login the installer found there or one set from its own product. See What Fleet can do and Other Wazuh products on your hosts.