Connect your Wazuh
Mobius reads alerts from your Wazuh through a connector that Wazuh Fleet installs and runs for you as the Mobius plugin. You get your host onto Wazuh Fleet, then add the environment from the Mobius console. Connecting takes a few minutes.
1. Install the Wazuh Fleet connector
Run the Wazuh Fleet connector one-liner on your Wazuh host. It enrolls the host into Wazuh Fleet and asks for nothing about your Wazuh indexer or manager:
curl -fsSL https://dl.fleet.wazuh.com/install.sh | sudo bash -s -- --token=<FLEET_TOKEN>
See the Wazuh Fleet documentation for the token and host requirements: Install the Fleet connector.
2. Add the environment from Fleet
In the console, open the Environments page, press Add environment, and choose Add environment from Fleet. Pick your environment from the list.
For an on-premises environment, the Mobius plugin first tries the Wazuh login already on the host, and the console asks for a Wazuh login only when that does not work, with the reason. A Wazuh Cloud environment asks for the login first, and there it is optional. Mobius tests the login on the host before the dialog finishes. Full details and troubleshooting: Install the connector.
3. Watch the first alerts arrive
Within a couple of minutes the environment turns Connected and the ingest cycle starts pulling recent alerts. Each one lands in the console already triaged: verdict, risk score, MITRE tags, and the analyst rationale.
Mobius pulls on demand through the connector's outbound session. If the connector goes down, nothing in your network is exposed. Mobius stops seeing new alerts, and the environment health card tells you so.