FAQ and troubleshooting
Most of these are questions about something that looks wrong and is not, or about a limit that is real and stated. Each answer is short, and links to the page that carries the detail where there is one.
They are all questions about Fleet: how a host is added, what a connector reports, and which service runs where. What a given Wazuh product does once allowed on a host is that product's own documentation.
Why does an environment show Detected and not Connected?
Detected means Fleet found the environment in your Wazuh Cloud account and no connector is deployed for it. It is not managed in Fleet, and everything shown for it comes from your Wazuh Cloud account rather than from the environment itself. Connected answers a different question, from a different vocabulary: a connector for it sent a heartbeat inside the last 90 seconds. An environment can be Active in Wazuh Cloud and have no connector reaching Fleet at the same time, which is why the two words are never collapsed into one. See The Hosts page.
Why is my host not on the Hosts page?
Three common causes, none of them a fault. A detected Wazuh Cloud environment is listed apart, under Detected in Wazuh Cloud on the Overview, until it is connected. A removed host leaves the list as soon as the removal commits. A member sees only the hosts granted to them.
Why does a host show Offline?
Offline means no heartbeat inside the same 90 second window the host's status
uses, re-derived against your browser's clock so a page left open ages
honestly rather than staying green. The usual causes are the connector being
stopped, egress to connect.fleet.wazuh.com on 443 being blocked, or an
expired client certificate, which renewal cannot repair because it authenticates
with the certificate the host still holds. On the host:
systemctl status fleet-connector
journalctl -u fleet-connector -f
sudo fleet-connector status
See Connector logs for the other units that log on the host, Connector lifecycle for renewal, and Install the connector for the re-enrolment command an expired identity needs.
Why did a Wazuh Cloud environment I removed come back as detected?
The detected grid is your Wazuh Cloud account de-duplicated against Fleet's registry, and the registry entry was the only thing hiding that environment from it. Remove the entry and the environment reappears under Detected in Wazuh Cloud on the very next list. Wazuh Cloud was asked to retire the Fleet connector it had deployed there, and nothing else about the environment changed. Pressing Connect to Fleet on that card brings it back. See Remove a host.
What does Connect to Fleet do on a Wazuh Cloud environment?
Fleet issues a one-hour enrolment token and asks Wazuh Cloud to deploy a Fleet connector inside the environment. It moves to Hosts in Fleet as Connecting and reads Connected on the connector's first heartbeat, a few minutes later. If it stays Connecting past the hour, or later goes Disconnected, the environment's detail page offers Connect again, which issues a new token and Wazuh Cloud replaces the connector. See Wazuh Cloud environments.
Why is there no Services panel on a Wazuh Cloud environment?
The connector Wazuh Cloud deployed for it does not report that it can host services yet. The panel appears once it does. Until then the detail page shows one sentence in its place and the API refuses any install on the environment with the same sentence. Wazuh Vesper is not available on Wazuh Cloud environments, by design. See Services on a Wazuh Cloud environment.
Can another Wazuh product use the connector I already installed?
Yes. The host your connector runs on can run another Wazuh product as a
service: a separate program, in its own process, under its own system
account, talking to its own product directly rather than through Fleet. Nobody
opens a shell on the machine. Three products ship a service today, Wazuh Vesper,
Wazuh Mobius and Wazuh Pharos, and each one has its own download host,
dl.vesper.wazuh.com, dl.mobius.wazuh.com and dl.pharos.wazuh.com, and its
own enrolment endpoint.
The download host and the enrolment endpoint are both compiled into the connector binary you installed rather than read from the message that asks for a service, and the download host is re-checked on every redirect hop, so a product's site is trusted for that product's service and for nothing else. Fleet allows a service on a host and the product installs it from its own console. The service gets no Fleet credential and no gateway address of its own. See Other Wazuh products on your hosts.
Why is an invitation still pending?
Two reasons read the same, and a third state does not. They have not followed the
link yet. Or the person already has a Fleet workspace of their own, in which case
the invitation stays pending until it expires, on purpose: an existing workspace
is never moved, because its hosts would stop being visible with no error
anywhere. The row reads Waiting for them to accept in both cases and nothing
distinguishes them, so ask them. A lapsed invitation is the state that does not
read as pending: one is valid for 14 days, and after that the row reads This invitation lapsed. Invite them again to send a new one. rather than being swept
away. See Team and access.
Why does a colleague see fewer hosts than I do?
Per-host grants. An administrator reaches every host in the workspace. A member
reaches only the ones ticked for them. The two states look identical in the data
and mean opposite things, so the role decides how to read them: an admin with no
grants has all hosts, a member with no grants has none. The grant is enforced by
the control plane on every request for a host rather than only hidden from a
list, and a host somebody has not been granted answers the same 404 Not found
as one that does not exist. See Team and access.
Why is a number missing instead of zero?
Because a zero is a claim and a failed read has not earned it. A tile whose figure nobody reported is absent, and a service whose status Fleet cannot read shows as unknown rather than as a state. That is the rule the whole console is built on: a value Fleet could not read is reported as a failed read, never as a zero. See The Hosts page.
Can Fleet read or change my Wazuh deployment?
No. Fleet reads a host's name, its platform and the connector on it, and the connector carries no path into your Wazuh at all. On a Wazuh node the installer finds the login Wazuh keeps there and hands it only to the services installed on that host, and that login never reaches Fleet. A compromise of Fleet cannot read or change a deployment, because there is nothing to ride. Reading a deployment, or acting on it, is a job for a service you allow on the host, with its own credentials and its own read-only discipline. See What Fleet can and cannot do.
Does Fleet store my Wazuh data?
No. Fleet keeps its own control plane and nothing from inside your machines: the host registry, your team with its roles and grants, and what each connector reports about itself and its machine, which is its version and last heartbeat, its certificate's serial and expiry, the host's name and platform, and the state of any service running on it. See What Fleet stores.
Something else
If it is about Fleet, take it to Getting help, which is the handoff to the people who can see your account. What is Fleet is the shape of the product and Add your first host is the path in. What a given Wazuh product does once allowed on a host is that product's own documentation.