Skip to main content

Getting help

Fleet has no ticket form of its own. The Help screen exists to send you to the place that can act: the Wazuh Cloud console, where the Wazuh Cloud team can see your account and your environments there. No Fleet screen opens or sends a support request.

Most of what people take to support, though, has a shorter answer in this documentation. The triage below is worth ten minutes before the handoff.

The Help screen​

Help is at /wazuh/support, in the Support group of the Wazuh Cloud sidebar. The screen carries one control, Get help in Wazuh Cloud, which opens console.cloud.wazuh.com/console/help in a new tab. Its own words are the reason for the handoff: support requests are handled in the Wazuh Cloud console, where the Wazuh Cloud team can see your account and environments.

Beside it, Documentation opens Wazuh's Cloud service documentation at documentation.wazuh.com, also in a new tab.

Both entries live on the Wazuh Cloud account surface, and that whole surface renders only once your session is paired to a Wazuh Cloud account. Until it is, every route under /wazuh sends you back to the pairing screen and the sidebar is not drawn, so this Help screen is not reachable if you run hosts of your own only. The link it carries is unconditional once you can see it: it points at the Wazuh Cloud console whether or not that console has anything to say about your environments.

Triage, in order of how often it is the answer​

SymptomWhat it usually isWhere it is answered
A host will not come ConnectedNo heartbeat inside the last 90 seconds. Check systemctl status fleet-connector and journalctl -u fleet-connector -f on the machineInstall the connector, Connector logs, Your own hosts
A host reads Connecting and stays thereA connector redeemed the token and has not sent its first heartbeat yetYour own hosts
Sign-in is refusedRare, since Fleet admits any signed-in Wazuh ID account. The screen names the reason: a session still naming a workspace you are no longer a member of, or a workspace of your own that cannot be merged into the one your organization already uses. A screen saying your access could not be confirmed means the check itself failed, most often Wazuh Hub not answering, and is the one worth retryingSign in
An invitation stays pendingPending means waiting for them to accept. The email comes from Wazuh, not from FleetTeam and access
Another Wazuh product's plugin on a host reads Could not tell or Crash-loopingFleet answers one question about a plugin, whether that process is alive and enrolled on that host. Whether the product itself is working is that product's own console, and the two disagreeing is a real stateOther services on your hosts

One case of the invitation row is worth knowing before it is reported as a bug: a person who already has a Fleet workspace of their own is never moved into the one they were invited to, because moving them would leave their own hosts behind. Their invitation stays pending, and their own console says so.

When a read fails​

Fleet reads its own control plane, not your deployments, so the reads that can fail are about which hosts you have and whether Fleet can reach each one. A failure does not render as a zero: a count nobody reported is absent, and a service whose status Fleet cannot read shows as unknown rather than as a state.

The failures worth telling apart are a refused session, a host that is not yours or is not granted to you, and a host whose connector Fleet cannot reach. The first sends you to Sign in. The second answers the same 404 Not found as a host that does not exist, which is deliberate, so a grant a colleague lacks is a Team question. The third is a machine question: check the connector there, as in the Connected triage above.

Is it Fleet, or is it my machine?​

playground.fleet.wazuh.com is the same console with its data layer replaced by fixtures. Open the screen there. If it renders and behaves, the code path is intact and the question is about the host or the read that reaches it. If it is broken there too, the product is broken, and that is worth reporting with the URL.

The playground signs nobody in, holds no API URL and reaches no machine, so it costs nothing to open. See The playground.

Questions about Wazuh rather than about Fleet​

Fleet does not read or change your Wazuh deployment. Rules and decoders, agent enrolment, manager configuration and the meaning of a rule level are Wazuh questions, and Wazuh's own documentation at documentation.wazuh.com is where they are answered.

Fleet does not touch your Wazuh

The console holds no Wazuh credential and the connector carries no path into your deployment, so Fleet reads nothing from it and changes nothing on it. What reads or acts on a deployment is a service you allow on the host, with the login the installer found there or one set from its own product. See What Fleet can do and Other Wazuh products on your hosts.