How the connector works
The connector exists to answer one question safely: how does a cloud service read your Wazuh alerts without you exposing anything?
Wazuh Fleet installs and runs the connector as the Mobius plugin on your host. See Install the connector for the onboarding steps.
The model: dial out, pull through
- The connector dials out over
:443with an mTLS identity issued at enrollment, and holds the session open. - Mobius pulls on demand. It sends read queries down the session, and the
connector executes them from your own network against the indexer on
:9200and the Wazuh manager API on:55000, then returns the results. - The connector never pushes data on its own. Nothing in your network listens for Mobius, and no inbound rule is opened for it.
The Wazuh login
Mobius reads an environment with a Wazuh login. On an on-premises host the plugin first tries the login already on the host, which the Wazuh Fleet installer passes to it when it found one there, and the console asks for a login only when that does not work. A login typed in the console reaches the connector on the host through Wazuh Fleet and always replaces the one found on the host. The plugin tests the login against the indexer and, when there is one, the Wazuh API, and reports the result back to the console.
Mobius does not store a typed login. It travels to the connector through Wazuh Fleet, so a reinstall of the Wazuh host needs it typed again. Updating it re-keys the running connector in place, without a reinstall and without dropping the session.
Guardrails
- Read-only allowlist. The connector only executes a fixed allowlist of
read operations. The single write path is the Incident Response action, a
separate, explicitly-gated call. It is permitted by default; the environment's
IR setting in Mobius is where it is turned on or off, and a machine owner can
opt a host out (
active_response.enabled: falsein the connector's configuration). The connector reports that choice on every heartbeat, so the console shows it and never sends a block to a host that opted out. See Incident response. - Per-target health probes ride the heartbeat, so the console can tell you which side of the connector is unhealthy, the indexer or the manager API.
- Single-use enrollment. The enrollment token activates exactly one connector. The plugin then runs with its mTLS identity, managed by Wazuh Fleet.
Why not expose the indexer?
Because Mobius reads alert data only through the session the connector dials out on, the indexer never has to accept a connection from outside. Nothing in your network listens for Mobius, and no inbound rule is opened for it.