Confirm the manager path first
The manager address must be reachable from the endpoint. A local web-dashboard URL is not necessarily the address used by agents. If a site uses a relay or VPN, verify the intended transport path and enrollment configuration before installing on several machines.
Avoid reusing another client's agent name or copying its authentication material. Correct identity matters as much as successful installation.
Use the current deployment instructions
- In the Wazuh dashboard, open the agent deployment workflow and select the Windows package matching the supported architecture and manager version.
- Supply the actual manager address, a unique agent name and the intended group.
- Review the generated installation command against the official Windows deployment documentation. Download only from the official source.
- Run it in an elevated Windows PowerShell session and check its result. Protect any enrollment secret; do not paste it into public notes.
Using the current generated command avoids publishing a tutorial with a permanently outdated MSI filename. A successful package download does not prove enrollment finished.
Check the local service
For the standard Windows package service name:
Get-Service -Name WazuhSvcStart the service using the supported deployment step if it is installed but not running. Inspect the agent's log and configuration in its actual installation directory; paths can differ by package and architecture. Keep an existing configuration before changing it.
Verify centrally
Confirm the expected agent name, group and fresh last-seen time. Generate a harmless event covered by your collection settings and search for it in the correct dashboard time range. Check that the event is attributed to the intended endpoint, not a stale duplicate record.
Common failures
Inactive status can come from a wrong manager address, blocked transport, enrollment failure, mismatched names or authentication problems. Dashboard HTTPS working does not prove native agent connectivity. Do not open all ports or disable the Windows firewall as a generic fix.
Rollout discipline
Complete one successful endpoint before repeating the process. Keep a small register of hostname, agent identity, group and verification time. Installation and fresh event delivery are separate acceptance checks. This uses free Wazuh software with your existing manager; it does not promise free cloud infrastructure for the central stack.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.