Wazuh fix note · dashboard

timeout of 20000ms exceeded

The Wazuh app in the dashboard waited 20 seconds for an answer and gave up. 20000 ms is the default of its Request timeout setting. The message means the other end accepted the request and did not answer in time: a slow or stuck Wazuh API, or a network path that swallows packets. A server that is simply down gives a different error, in milliseconds.

Dong Nguyen, ATK New Technology · 2 October 2026 · measured in a Wazuh 4.14.7 dashboard container

Stuck on this right now? Email your custom rules or decoders, one sample log line and your Wazuh version to dongnx@atkvn.com. We run them on that exact version and reply within 24 hours with what we find. Free. Remove hostnames, IPs and usernames first. Rather not send them? Run the free pre-check in your browser; your files never leave your machine. Rather have it fixed? USD 149 fixed price per problem, reproduced on your version, and you pay only after it works on your system. Our first three customers pay USD 49 for one fix, in exchange for an anonymised write-up we can publish.


How to check in one minute

From the dashboard host, time the Wazuh API directly (use the URL and port from the dashboard's API connection):

curl -sk -o /dev/null -w 'HTTP %{http_code} in %{time_total}s\n' https://WAZUH_API:55000/
  • Answers in well under a second (a 401 is fine, it means no credentials were sent): the API is up. The timeout comes from one slow call; see step 2.
  • Hangs: something between the dashboard and the API drops packets, or the API is stuck. Check firewalls and the API process.
  • Connection refused immediately: the API is down or on another port. That is a different problem and normally a different message.

2. Find the slow call. On the manager, the API log records each request with its duration:

tail -n 50 /var/ossec/logs/api.log

Each line ends like "GET /manager/stats/analysisd" ... done in 0.029s: 200. Reproduce the page that fails, then list the slowest requests:

sed -n 's/.*INFO: [^ ]* [^ ]* "\([A-Z]* [^"]*\)".* done in \([0-9.]*\)s.*/\2 \1/p' /var/ossec/logs/api.log | sort -rn | head -n 10

It prints the duration in seconds, then the request, slowest first.

Why it happens

In wazuh-dashboard-plugins 4.14.7, the app's request service (plugins/main/public/react-services/wz-request.ts) sets timeout = configuration.timeout, falling back to 20000. The setting is defined in wazuh-core/common/constants.ts as Request timeout: "Maximum time, in milliseconds, the app will wait for an API response", default 20000, minimum 1500.

The text itself is the HTTP client's (axios) timeout message. We ran the axios build shipped in the 4.14.7 dashboard container (1.12.2) with the same 20000 ms timeout:

Target (from inside the dashboard container)Result
a port that accepts the connection and never answersECONNABORTED, "timeout of 20000ms exceeded", after 20,030 ms
a closed portECONNREFUSED, after 24 ms

So the message points at slowness or a silent drop, not at a stopped service.

Fix

1. Fix the slow part first. A request that takes more than 20 seconds usually comes from a heavy query (large agent lists, big inventories, wide time ranges), an overloaded manager, or a network device dropping traffic to port 55000. The API log from step 2 tells you which.

2. If the work is legitimately slow, raise the limit. In the dashboard: Dashboard management → App settings → General → Request timeout, in milliseconds. The same key, timeout, can be set in the app's configuration file. Raising it hides a slow API; it does not make it faster.

Limits of what we measured

We measured the client side only: the exact message and timing from the dashboard's own axios build against a silent port and a closed port, inside our 4.14.7 dashboard container. That the Wazuh app passes its Request timeout setting to these requests comes from reading the 4.14.7 source. We did not reproduce a slow Wazuh API end to end through the dashboard UI, and we did not measure which pages are slowest at scale. Menu names may differ between versions.

Have it working

Dashboard still timing out? Send the page that fails, the matching lines from api.log (masked) and your Wazuh version to dongnx@atkvn.com. We reply within 24 hours with what we find. Free. Rather have it fixed for you? USD 149 fixed price per problem, paid after it works on your system.