Skip to main content

Install the connector

Mobius reads your alerts through a connector, and Wazuh Fleet installs and runs it for you as the Mobius plugin. Onboarding is two steps: get your Wazuh hosts onto Wazuh Fleet, then add the environment from the Mobius console. There is no Mobius command to run on a host.

The connector is outbound-only. It opens one secure session out to connect.mobius.wazuh.com and answers Mobius's read requests from inside your network, so no inbound port is opened for Mobius. See How the connector works.

Before you start​

  • You are an admin of your Mobius workspace.
  • Your workspace belongs to a Wazuh organization (the one Wazuh Fleet knows).
  • Your Wazuh hosts are Linux on x86_64 or arm64.

Step 1: Install the Wazuh Fleet connector on your host​

Run the Wazuh Fleet connector one-liner on the host of your Wazuh deployment. This enrolls the host into Wazuh Fleet. It asks for nothing about your Wazuh indexer or manager, and it installs no Mobius software by itself:

curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<FLEET_TOKEN>

Get the token and the full host requirements from the Wazuh Fleet documentation: Install the Fleet connector. The host must have checked in to Fleet at least once before Mobius can use it.

Step 2: Add the environment from Fleet​

  1. In the Mobius console, open the Environments page and press Add environment.
  2. Choose Add environment from Fleet. Mobius lists the Fleet environments in your organization, each showing its hosts and whether a connector is online.
  3. Press Add on the environment.

Step 3: The Wazuh login​

An on-premises environment is added with no login. Wazuh Fleet installs the Mobius plugin, and the plugin first tries the Wazuh login already on the host, which the Wazuh Fleet installer passes to it when it found one there. When that login works, the environment is ready and no form appears. When it does not, the dialog opens the login form and says why, such as no Wazuh login found on the host, a login Wazuh rejected, or a plugin that did not report within two minutes of coming up. Type the login instead opens the same form at any time while the plugin is trying, and a typed login always replaces the one found on the host.

A Wazuh Cloud environment opens the login form first. There the login is optional, because its indexer is reachable with the account Wazuh already provisions, and Add without a login skips it.

The form takes these fields, and Mobius tests the login on the host before the dialog finishes.

FieldRequiredExample
Indexer API URL / Username / PasswordYeshttps://127.0.0.1:9200, admin
Wazuh API URL / Username / PasswordOptionalhttps://127.0.0.1:55000, wazuh
CA certificateOptionalPaste the PEM to verify the indexer and Wazuh API TLS chain
Skip TLS verificationOptionalOn by default. Pasting a CA overrides and disables it.

The Indexer API login is what Mobius reads alerts from, so it is required. The Wazuh API login is optional and adds agent detail and, where enabled, Incident Response. A read-only Wazuh login is enough for triage.

The URLs are dialled from the Wazuh host itself, where the plugin runs, not from Mobius. A default Wazuh install binds the indexer to the loopback address only, so type https://127.0.0.1:9200 unless the indexer is bound to the machine's network address.

Mobius hands a typed login to the connector through the encrypted Wazuh Fleet channel and does not keep it. After a reinstall of the Wazuh host, a typed login is entered again. It can be changed later. See Update or fix the Wazuh login.

On Wazuh Cloud, Add environment connects with the typed login. In the dialog of an on-premises environment, Test this login sends the typed login to the host and tests it.

What happens after you connect​

The environment shows Connecting while Wazuh Fleet installs the Mobius plugin on the host and enrolls it, usually in under a minute. The plugin then tries the login, the one found on the host or the one typed, and the console shows the result:

  • The Wazuh login works. The indexer, and the Wazuh API if you supplied one, accepted the login.
  • The indexer login works. No Wazuh API login was found on this host. Mobius reads the environment's alerts. Set credentials adds a Wazuh API login.
  • The Wazuh API did not accept this login. Mobius can still read the environment's alerts through the indexer. You can open the environment and fix the Wazuh API login later.
  • The Wazuh login did not work, or No Wazuh login yet. Use Change credentials in the same dialog to re-enter the login and test it again, without starting over. When the host could not reach a URL at all, the result names that URL. If it is not a loopback address, it also points at https://127.0.0.1 on the same port, where a default install listens.

A host that is offline right now joins when it comes back.

Verify​

The environment turns Connected and the ingest cycle starts pulling recent alerts. Each one lands already triaged: verdict, risk score, MITRE tags, and the analyst rationale. The environment card shows the indexer and Wazuh API as reachable separately, each with its detected cluster name and version.

Update or fix the Wazuh login​

When a password rotates on the Wazuh side, or a login was entered wrong, update it from the environment page: enter the new Wazuh login and Mobius re-keys the running plugin in place. There is no reinstall and the session is not dropped. The new login replaces the one the connector holds and is tested on the host the same way.

If an environment cannot be connected​

The list names the reason an environment is unavailable:

  • Already added to Mobius. It is on the Environments page.
  • Allow Mobius on this host in Fleet first. Open the host in Fleet and allow Mobius in its Services panel. The environment can then be added. A Wazuh Cloud environment reads "on this environment".
  • No connector online for this environment. Finish Step 1 on the host and wait for it to check in to Fleet.
  • Not part of a Wazuh organization. Fleet has no organization to find it by.
  • No plugin release available yet. Mobius has no published plugin for Fleet to install. This is ours to fix, not yours.

An environment whose connect did not finish shows Connect again. Select it to finish the connect. The environment keeps its name and settings.

Disconnect​

Disconnect an environment from its page in the Mobius console. Wazuh Fleet removes the Mobius plugin from the host. Disconnecting stops the reporting and nothing else: the environment, its alerts, and its history stay in Mobius.

Delete​

Deleting an environment is different from disconnecting it: it removes the environment and all of its data permanently. Alerts, incidents, reports, response actions, false positive rules and knowledge written for it, cases about only this environment, and its notifications are gone. Other environments are not affected, and billing and usage records are kept for invoicing.

Only an admin can delete an environment, and the console asks you to type the environment's name before the button enables. The name is checked again by Mobius itself, so a script or an older client cannot skip the confirmation. A large environment is removed in the background over a few minutes; its page disappears immediately.