Environments
An environment is one Wazuh deployment the agent works on: a production cluster, a staging setup, a lab. An all-in-one Wazuh is an environment with one node. A distributed Wazuh is one environment with a node for the manager master, each worker, each indexer and the dashboard, and the agent treats it as a unit: one conversation, with the agent choosing which node to read or act on. Environments are managed on the Environments page. Registering and deleting them, changing their agent mode and removing nodes are admin actions.
Register an environment
- Install the Wazuh Fleet connector on the hosts of the Wazuh deployment, and allow Vesper on each host in Wazuh Fleet.
- Open Environments and choose Add. The panel lists the hosts Wazuh Fleet governs, one checkbox each.
- Tick the hosts of the deployment, type a name for the environment and choose Add and connect. The name accepts letters, digits, spaces, apostrophes, dots, dashes and underscores, up to 64 characters. Wazuh Fleet installs Vesper's plugin on each ticked host. Each host enrolls as its own node and starts dialing out to Vesper. See Install the connector.
Add hosts, on the environment's Wazuh Fleet card, adds more hosts later. A host is in one environment at a time.
Connector status
Each environment card shows the state of the environment as a whole:
| Status | Meaning |
|---|---|
| Waiting for connector | Registered, but no connector has enrolled yet. |
| Connector online | At least one node's connector reported in the last 90 seconds. This says the connector is reporting, not that Wazuh answers it. |
| Connector offline | Connectors enrolled before, but none has reported in the last 90 seconds. |
When the connector is online but the Wazuh indexer or the Wazuh API is not answering it, the Connector card says so in one line above the readings, and the readings name which part failed.
The card summarizes the environment in numbers, such as "7 nodes, 6 reachable, 1 without a connector", and the node view under it names each node.
The node view
One card per machine, grouped by what the machine is: managers in one group, with the master and its workers, indexers in another, dashboards in a third. An all-in-one is one card holding all three components. Each group folds and unfolds on a click and its header counts the machines in it and how many are reachable, so a large deployment reads in three lines. Each card shows the name an admin gave the node, when there is one, above the name its own Wazuh configuration gives it, then the components it runs with their versions, its state, when its connector last reported, the connector's build, and anything that failed.
A click on a card's name opens it. The open card shows what the node reported, grouped as host, cluster, reachability and connector: address, platform, cluster name and role, the two probes with their latency, the last heartbeat, the connector build, its certificate fingerprint and serial, when it enrolled and the outcome of its last upgrade. A fact the node did not report reads Not reported.
| State | Meaning |
|---|---|
| Reachable | The node's connector reported within the last 90 seconds. |
| Unreachable | The node has a connector and it has stopped reporting. The card stays until an admin removes it. |
| No connector | Wazuh lists this node in its cluster and no connector is installed on it. The agent cannot read or fix anything there. |
A target the node does not have, such as the indexer on a manager worker, reads not on this node. That is not a failure and is never shown as unreachable.
Remove node, on a node with a connector, revokes that node's identity and takes it off the view. Nothing changes on the machine itself. A host added from Wazuh Fleet offers Disconnect this host in its place, which also removes Vesper's plugin from the host and leaves the host free to add again. See Connector lifecycle.
The kinds a node can report are all in one, manager master, manager worker, manager, indexer, dashboard, mixed and unknown. A node reporting unknown is a host where the connector found no Wazuh component, and the agent is told not to assume any layout for it.
Rename a node
Wazuh's default node names, such as node01, are the same on every
installation. An admin can give a node a display name, such as Madrid manager,
with the pencil next to its name on the card or in the open card. Enter saves
the name and Escape cancels the edit. Members who are not admins see no pencil,
and a node with no connector has nothing to rename.
A display name uses letters, digits, spaces, dots, dashes and underscores, up to 64 characters. Anything else is refused, and the reason shows under the field. An empty name goes back to the name the node reports.
Under a display name, the card still shows the name the node reports, so the machine stays identifiable. The agent and the approval card use the display name too. The agent also keeps the name Wazuh reports, because that is the name Wazuh's own cluster tools use.
A display name is only a label. The node's identity does not change, and neither does anything the agent can do on it. A change recorded before a rename keeps the name the node had at the time. A host from Wazuh Fleet that is disconnected and added back to the same environment keeps its display name. A connector installed by hand starts without one after a reinstall.
Agent mode
The environment card carries the agent mode selector, with Read only, Manual and Auto. The mode is the per-environment ceiling for what the agent may do, and only admins can change it.
The same selector sits at the end of the composer row on the Agent page, so the ceiling can be raised or lowered without leaving a conversation. A change applies to the whole team and takes effect on the next command the agent runs. A member who is not an admin sees the current mode and cannot change it.
Removing a connector or an environment
An environment whose connectors were installed by hand, before Wazuh Fleet, offers the uninstall one-liners on its card, independent of the connector's state:
# stop and remove the connector, keep its config
curl -fsSL https://dl.vesper.wazuh.com/uninstall.sh | sudo bash
# remove everything, including config and the enrolled identity
curl -fsSL https://dl.vesper.wazuh.com/uninstall.sh | sudo bash -s -- --purge
Deleting the environment in the console revokes every node's connector server-side. Revoke all connectors does the same and keeps the environment.
Revoking a connector without removing it, recovering one whose identity has expired, and moving to a new build are covered in Connector lifecycle.