Command reference
Three programs make up the connector's command line on a host. The
fleet-connector binary is the daemon and the operator's tool. install.sh
installs, updates and re-enrolls a host. uninstall.sh removes the connector
from it. Every command below runs on the host itself and needs root, except
fleet-connector version.
fleet-connector
The first word selects a subcommand, and it has to come first. Any other bare
first word is refused with fleet-connector: unknown command "<word>" and the
list of commands, and a known subcommand placed after a flag is refused with
fleet-connector: put the subcommand first. Neither starts anything.
| Command | What it does | What it never does | Example |
|---|---|---|---|
status | Prints the update ledger. The running version and its path, the previous binary kept for a rollback, every installed version, what is staged or pending confirmation, the last outcome, and for each plugin what current points at, the unit's state and the versions installed. | Change anything, or contact Fleet. A unit state it could not read prints as unknown, never as stopped. | sudo fleet-connector status |
rollback [core|plugin:<service>] [--to <version>] | Puts back a version already on the host and restarts its unit. With no component it acts on the connector. With no --to, the connector goes back to its previous binary, and a plugin goes back to its previous version only until the confirm step has judged the swap. After that, name the version with --to, as fleet-connector status lists them. The undone version is recorded as failed, so it is not offered to the host again automatically. --rollback is accepted as the same command. | Download anything. A version that is not installed on the host is refused. | sudo fleet-connector rollback plugin:pharos --to 1.4.0 |
reconcile | Installs what the daemon staged and performs the plugin acts Fleet asked for. It runs as root with no network and exits. systemd runs it, and running it by hand is safe. | Download anything, or install something the daemon did not stage. | sudo fleet-connector reconcile |
provision [flags] | Writes /etc/fleet-connector/connector.yaml. The installer runs it. --dry-run prints the file instead of writing it. | Detect anything on the host, ask for credentials, or overwrite an existing file without --force. A rewrite keeps the runtime and upgrade values. | sudo fleet-connector provision --dry-run |
discover [--data-dir <path>] [--remove] | Looks for the Wazuh login the host keeps, reading files only, and writes it to discovered-login.json in the data directory when it finds a full indexer login. A run that finds nothing deletes an older file. --remove reads nothing and deletes the file, which stops delivery and revokes nothing. The installer runs it. See The Wazuh login the installer finds. | Open a connection, run another program, print a username or a password, or change a login a service already holds. | sudo fleet-connector discover |
version | Prints the version. --version is the same. | Start the daemon. | fleet-connector version |
Flags of provision
| Flag | What it sets |
|---|---|
--config <path> | The file to write. The default is /etc/fleet-connector/connector.yaml. |
--connect <wss URL> | The gateway address written into the file. |
--enroll <URL> | The enrolment address, derived from --connect when absent. |
--data-dir <path> | The data directory pinned in the file. The default is /var/lib/fleet-connector. |
--force | Overwrite an existing file. |
--dry-run | Print the file and write nothing. |
Flags of the daemon
With no subcommand the binary is the daemon, which systemd starts as
fleet-connector --config /etc/fleet-connector/connector.yaml.
| Flag | What it does |
|---|---|
--config <path> | The configuration file. The default is /etc/fleet-connector/connector.yaml, and /etc/mobius/connector.yaml is read instead only while the default file does not exist. |
--token <token> | Enrols with this token before starting, replacing any stored identity. |
--connect <wss URL> | Overrides the gateway address in the file for this run. |
--enroll-only | Enrols and exits. The installer uses it. |
Starting the daemon by hand while fleet-connector.service is running gives the
host two connectors with one identity. Restart the service instead with
sudo systemctl restart fleet-connector.
install.sh
curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<TOKEN>
| Flag | What it does | What it never does | Example |
|---|---|---|---|
--token=<TOKEN> | Enrols a host that has no connector yet. The token is single use and valid for one hour. | Replace the identity of a host that already has a connector. | --token=<TOKEN> |
--re-enroll | Replaces the host's identity with a new one, which also moves the machine to another host entry in Fleet. Needs --token. | Run without a token. | --re-enroll --token=<TOKEN> |
--force | Rewrites connector.yaml even though one exists, keeping its runtime and upgrade values. | Touch the identity. | --force |
--connect=<wss URL> | Overrides the gateway. The default is wss://connect.fleet.wazuh.com. | Change which download site is used. | --connect=wss://connect.fleet.wazuh.com |
--allow-unverified | Installs the binary when no checksum is published for it, or when the host can compute none. The log says so as a warning. | Install a binary whose checksum was computed and does not match. | --allow-unverified |
--no-discover | Skips the search for the Wazuh login the host keeps, and deletes the one an earlier run found. Deleting it stops delivery and revokes nothing: a service that already took the login keeps it until a login is set from that service or the service is removed. | Change a login a service already holds. | --no-discover |
| A token on a host that already has a connector | Stops the install before anything is downloaded and names the two ways on: --re-enroll for the identity, or remove --token and add --force for the configuration. | Report success while keeping the old identity. | See Install the connector |
Running the installer again with no flag updates the host: it keeps the
identity and the config and installs the current binary and units.
MOBIUS_DOWNLOAD_BASE in the environment points the downloads at a mirror. Any
other argument stops the install with unknown argument, and the installer
takes no typed Wazuh credentials in any form. The only Wazuh login it handles is
the one it finds on the host.
uninstall.sh
curl -fsSL https://dl.fleet.wazuh.com/uninstall.sh | sudo bash
curl -fsSL https://dl.fleet.wazuh.com/uninstall.sh | sudo bash -s -- --purge
| Mode | What it does | What it never does |
|---|---|---|
| No flag | Stops and disables every plugin first, then the connector and its units. Removes the binary, the previous binary, every unit file, every exec drop-in, the confirm script and the Wazuh login the installer found. | Remove the identity, the config, the installed versions or the plugin users. The host stays listed in Fleet. |
--purge | Everything above, plus /var/lib/fleet-connector, /etc/fleet-connector, /usr/local/lib/fleet-connector and the fleet-plugin-<service> users. With no Wazuh Mobius connector on the host it also removes /etc/mobius/connector.yaml and /var/lib/mobius-connector. | Touch a Wazuh Mobius connector's files, or remove the host from Fleet. |
Removing a host from Fleet is a separate act in the console. See Remove a host. The full list of paths is in What the installer puts on a host.