Skip to main content

Command reference

Three programs make up the connector's command line on a host. The fleet-connector binary is the daemon and the operator's tool. install.sh installs, updates and re-enrolls a host. uninstall.sh removes the connector from it. Every command below runs on the host itself and needs root, except fleet-connector version.

fleet-connector​

The first word selects a subcommand, and it has to come first. Any other bare first word is refused with fleet-connector: unknown command "<word>" and the list of commands, and a known subcommand placed after a flag is refused with fleet-connector: put the subcommand first. Neither starts anything.

CommandWhat it doesWhat it never doesExample
statusPrints the update ledger. The running version and its path, the previous binary kept for a rollback, every installed version, what is staged or pending confirmation, the last outcome, and for each plugin what current points at, the unit's state and the versions installed.Change anything, or contact Fleet. A unit state it could not read prints as unknown, never as stopped.sudo fleet-connector status
rollback [core|plugin:<service>] [--to <version>]Puts back a version already on the host and restarts its unit. With no component it acts on the connector. With no --to, the connector goes back to its previous binary, and a plugin goes back to its previous version only until the confirm step has judged the swap. After that, name the version with --to, as fleet-connector status lists them. The undone version is recorded as failed, so it is not offered to the host again automatically. --rollback is accepted as the same command.Download anything. A version that is not installed on the host is refused.sudo fleet-connector rollback plugin:pharos --to 1.4.0
reconcileInstalls what the daemon staged and performs the plugin acts Fleet asked for. It runs as root with no network and exits. systemd runs it, and running it by hand is safe.Download anything, or install something the daemon did not stage.sudo fleet-connector reconcile
provision [flags]Writes /etc/fleet-connector/connector.yaml. The installer runs it. --dry-run prints the file instead of writing it.Detect anything on the host, ask for credentials, or overwrite an existing file without --force. A rewrite keeps the runtime and upgrade values.sudo fleet-connector provision --dry-run
discover [--data-dir <path>] [--remove]Looks for the Wazuh login the host keeps, reading files only, and writes it to discovered-login.json in the data directory when it finds a full indexer login. A run that finds nothing deletes an older file. --remove reads nothing and deletes the file, which stops delivery and revokes nothing. The installer runs it. See The Wazuh login the installer finds.Open a connection, run another program, print a username or a password, or change a login a service already holds.sudo fleet-connector discover
versionPrints the version. --version is the same.Start the daemon.fleet-connector version

Flags of provision​

FlagWhat it sets
--config <path>The file to write. The default is /etc/fleet-connector/connector.yaml.
--connect <wss URL>The gateway address written into the file.
--enroll <URL>The enrolment address, derived from --connect when absent.
--data-dir <path>The data directory pinned in the file. The default is /var/lib/fleet-connector.
--forceOverwrite an existing file.
--dry-runPrint the file and write nothing.

Flags of the daemon​

With no subcommand the binary is the daemon, which systemd starts as fleet-connector --config /etc/fleet-connector/connector.yaml.

FlagWhat it does
--config <path>The configuration file. The default is /etc/fleet-connector/connector.yaml, and /etc/mobius/connector.yaml is read instead only while the default file does not exist.
--token <token>Enrols with this token before starting, replacing any stored identity.
--connect <wss URL>Overrides the gateway address in the file for this run.
--enroll-onlyEnrols and exits. The installer uses it.

Starting the daemon by hand while fleet-connector.service is running gives the host two connectors with one identity. Restart the service instead with sudo systemctl restart fleet-connector.

install.sh​

curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<TOKEN>
FlagWhat it doesWhat it never doesExample
--token=<TOKEN>Enrols a host that has no connector yet. The token is single use and valid for one hour.Replace the identity of a host that already has a connector.--token=<TOKEN>
--re-enrollReplaces the host's identity with a new one, which also moves the machine to another host entry in Fleet. Needs --token.Run without a token.--re-enroll --token=<TOKEN>
--forceRewrites connector.yaml even though one exists, keeping its runtime and upgrade values.Touch the identity.--force
--connect=<wss URL>Overrides the gateway. The default is wss://connect.fleet.wazuh.com.Change which download site is used.--connect=wss://connect.fleet.wazuh.com
--allow-unverifiedInstalls the binary when no checksum is published for it, or when the host can compute none. The log says so as a warning.Install a binary whose checksum was computed and does not match.--allow-unverified
--no-discoverSkips the search for the Wazuh login the host keeps, and deletes the one an earlier run found. Deleting it stops delivery and revokes nothing: a service that already took the login keeps it until a login is set from that service or the service is removed.Change a login a service already holds.--no-discover
A token on a host that already has a connectorStops the install before anything is downloaded and names the two ways on: --re-enroll for the identity, or remove --token and add --force for the configuration.Report success while keeping the old identity.See Install the connector

Running the installer again with no flag updates the host: it keeps the identity and the config and installs the current binary and units. MOBIUS_DOWNLOAD_BASE in the environment points the downloads at a mirror. Any other argument stops the install with unknown argument, and the installer takes no typed Wazuh credentials in any form. The only Wazuh login it handles is the one it finds on the host.

uninstall.sh​

curl -fsSL https://dl.fleet.wazuh.com/uninstall.sh | sudo bash
curl -fsSL https://dl.fleet.wazuh.com/uninstall.sh | sudo bash -s -- --purge
ModeWhat it doesWhat it never does
No flagStops and disables every plugin first, then the connector and its units. Removes the binary, the previous binary, every unit file, every exec drop-in, the confirm script and the Wazuh login the installer found.Remove the identity, the config, the installed versions or the plugin users. The host stays listed in Fleet.
--purgeEverything above, plus /var/lib/fleet-connector, /etc/fleet-connector, /usr/local/lib/fleet-connector and the fleet-plugin-<service> users. With no Wazuh Mobius connector on the host it also removes /etc/mobius/connector.yaml and /var/lib/mobius-connector.Touch a Wazuh Mobius connector's files, or remove the host from Fleet.

Removing a host from Fleet is a separate act in the console. See Remove a host. The full list of paths is in What the installer puts on a host.