# Windows Event 7009 - A timeout was reached (30000 milliseconds) while waiting for the Elastic Agent service to connect

**URL:** <https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052>\
**Category:** Elastic Security\
**Created:** [October 28, 2025, 5:30pm UTC](https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052 "2025-10-28T17:30:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bgreen99](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@bgreen99](https://discuss.elastic.co/u/bgreen99)\
**Post date:** [October 28, 2025, 5:30pm UTC](https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052/1 "2025-10-28T17:30:37Z")

</div>

We are often getting a windows event code 7009 post reboot regarding elastic agent service not starting indicating: _**A timeout was reached (30000 milliseconds) while waiting for the**_ _ **Elastic** _ _ **Agent service to connect.** _ This prevents the process endpoint-security.exe from running.

When we manually start the service after it starts up it shows online and healthy in fleet. My question is, when the service fails to start with a 7009 event code, does that mean there is no endpoint security protection on the host until the service is started successfully?

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [October 28, 2025, 5:44pm UTC](https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052/2 "2025-10-28T17:44:06Z")

</div>

As long as Endpoint security is starting properly and was previously working, it should start up and be running with the same policy that it was running with before the reboot.

We recently added a mitigation to help with this in the advanced policy section for endpoint that you could try setting to true. (but note that it will not take effect if Agent isn’t already running to delivery that new configuration to endpoint).

The Agent team is working on a complete fix to this issue that will hopefully be out soon (hopefully next minor, but thats not my team so I can’t commit them to that).

---

<div class="post-metadata">

**Author:** ![bgreen99](https://avatars.discourse-cdn.com/v4/letter/b/67e7ee/32.png) [@bgreen99](https://discuss.elastic.co/u/bgreen99)\
**Post date:** [October 28, 2025, 6:20pm UTC](https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052/3 "2025-10-28T18:20:18Z")

</div>

Thanks Nick, just to clarify. It didn’t start properly hence the 7009 event code reflecting process was not running. Is the host still protected if endpoint-security.exe process/service fails to start?

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [October 29, 2025, 8:31am UTC](https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052/4 "2025-10-29T08:31:08Z")

</div>

You should have two services. Elastic Agent (elastic-agent.exe) and Elastic Endpoint (elastic-endpoint.exe)

What I have generally seen is that the Elastic Agent service will fail to start due to timeout with the 7009 error but Elastic Endpoint will start properly.

In order for the host to be protected, Elastic Endpoint will need to be running. If you’re experiencing a 7009 error for the Elastic Endpoint service, that is something that is unusual and I would like to have someone on my team look into it further.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [October 31, 2025, 12:55pm UTC](https://discuss.elastic.co/t/windows-event-7009-a-timeout-was-reached-30000-milliseconds-while-waiting-for-the-elastic-agent-service-to-connect/383052/5 "2025-10-31T12:55:04Z")

</div>

> [@bgreen99](#):
>
> Is the host still protected if endpoint-security.exe process/service fails to start?

Not when `elastic-security.exe` fails to run, but when only `elastic-agent.exe` fails to run.

This is why`Orphaned` indicator was added. It’s role is to tell you that Elastic Endpoint service is running and protecting the host, but it can’t communicate with Elastic Agent thus is unreachable from the stack for exceptions updates, host isolation toggle, any response actions…

Unfortunately we’re dealing with some corner cases where `Orphaned` state is falsely reported on HEALTHY setup, but we’ll eventually clean these issues
