Skip to main content

Connect your Wazuh

Mobius reads alerts from your Wazuh through a connector that Wazuh Fleet installs and runs for you as the Mobius plugin. You get your host onto Wazuh Fleet, then add the environment from the Mobius console. Connecting takes a few minutes.

1. Install the Wazuh Fleet connector​

Run the Wazuh Fleet connector one-liner on your Wazuh host. It enrolls the host into Wazuh Fleet and asks for nothing about your Wazuh indexer or manager:

curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<FLEET_TOKEN>

See the Wazuh Fleet documentation for the token and host requirements: Install the Fleet connector.

2. Add the environment from Fleet​

In the console, open the Environments page, press Add environment, and choose Add environment from Fleet. Pick your environment from the list.

For an on-premises environment, the Mobius plugin first tries the Wazuh login already on the host, and the console asks for a Wazuh login only when that does not work, with the reason. A Wazuh Cloud environment asks for the login first, and there it is optional. Mobius tests the login on the host before the dialog finishes. Full details and troubleshooting: Install the connector.

3. Watch the first alerts arrive​

Within a couple of minutes the environment turns Connected and the ingest cycle starts pulling recent alerts. Each one lands in the console already triaged: verdict, risk score, MITRE tags, and the analyst rationale.

note

Mobius pulls on demand through the connector's outbound session. If the connector goes down, nothing in your network is exposed. Mobius stops seeing new alerts, and the environment health card tells you so.