Documentation
Find the answer,
don't hunt for it.
Using, administering and integrating FirstSI. Type your question: search reads every page, section by section.
Most read: Install the agent · NetDiag: workstation network diagnostics · Ticket pre-diagnostics · API tokens · An agent doesn't show up or stays offline · Two-factor authentication
Getting started
First steps: sign in, find your way around, install the agent.
- Discover FirstSIWhere FirstSI gets its data, and which module to open for the question you have.
- Sign inSigning in with an email address or your company account (SSO), the second factor, and how long a session lasts.
- Find your way around the consoleThe per-module menu, global search, real-time notifications, language and theme.
- Install the agentDownload the MSI, choose the modules, install by hand or at scale, check it works, uninstall.
- First settings (administrator)What an administrator sets up in the first week, in an order that avoids going back over things.
Using FirstSI
Every module, screen by screen, for support and operations.
- DashboardOverall IT health, what is still waiting to be handled, and one line per module.
- Alerts and notificationsWhere each module's alerts end up, how to handle them, and how to get notified by e-mail, Teams or Slack.
- NetDiag: workstation network diagnosticsRead a workstation's verdict, find out what is to blame when the connection drops (PC, Wi-Fi, LAN, Internet, DNS, service), run a traceroute, a speed test or a packet capture.
- AI assistantAsk a question in plain language. The assistant reads your data across the modules, cross-checks what it finds and cites its sources.
- FileMonitor: file accessFind out who read, changed, deleted or renamed a file on a file server, and choose which folders are monitored.
- Workstation network flowsEvery connection a workstation or server makes, with the process, the user, the destination and the volume.
- Flow explorerSlice flows from workstations, gateways and the firewall by country, service, process… with a chart, a Sankey diagram and filters.
- Investigate a deviceEverything FirstSI knows about an IP address or a workstation name, on a single page.
- Firewalls and gatewaysReceive syslog and IPFIX flows from your firewalls, declare devices, watch collection, authentication failures and threats.
- DNS MonitorDomain names looked up by workstations, checked against lists of malicious domains (malware, C2, phishing).
- HostMonitor: service availabilityMonitor websites, ports, certificates, databases, Windows services and folders; incidents, maintenance, escalation and status page.
- NetworkMonitor: sites, devices, tunnelsInventory of sites and network devices, SD-WAN tunnels, WAN links, Wi-Fi, topology, host presence, open ports and alert rules.
- DBMonitor: databasesSQL Server and MariaDB performance, slow queries, sessions, blocking, waits, and business control queries.
- SI-Tracer: Windows authenticationWho signed in where, failures, Kerberos, NTLM, directory changes, logon graph, accounts at risk and anomalies.
- SI-Map: application mappingDescribe your applications, their criticality, their owners and the servers they depend on; spot orphan assets and undocumented flows.
- AssetMonitor: inventory, vulnerabilities, licensesInventory of machines and software, known vulnerabilities (CVEs), end of support, actual software usage, license compliance and alerts.
- SIEM: correlation and security incidentsThe rules that cross-check events from the modules, an incident's life cycle, response times (SLA) and notifications.
- Microsoft 365Understand why a Microsoft 365 or SSO sign-in is refused, check an account and its multi-factor authentication, follow Microsoft incidents; connect the connector.
- Google WorkspaceTablets and phones managed by Google, versions of installed apps, domain accounts; setting up the service account.
- PDF reportsGenerate a report on demand, or receive one by e-mail every day, week or month.
- Account profile and IP address profileEverything about an account on one page (logons, failures, lockouts and their real origin, VPN, Microsoft 365), and where an IP address comes from.
Administration
Accounts, security, agents, connectors and organisation settings.
- Users and rolesCreate accounts, pick the role, restrict visible modules, disable an account or reset its two-factor authentication.
- Two-factor authenticationTurn on an authenticator app (TOTP) or a security key, keep your backup codes safe, and what to do if you lose your phone.
- Customer security and SSOAllowed sign-in methods, mandatory two-factor authentication, company sign-in (Entra ID, Okta, Google, OIDC), sign-out after inactivity.
- Customer settingsWhat each settings tab contains, the agent registration key and email sending (SMTP).
- Data, GDPR and audit logHow long data is kept, how to turn purging on, and where to find who did what in the console.
- Manage agentsSwitch a module on or off remotely, update the fleet, choose the update policy, remove an agent.
- Agent network egress (relays and proxy)Route agents on a network without Internet access through another FirstSI agent or the company proxy.
- Connectors: read your applicationsConnect a REST API or a SQL Server database read-only, write a query or have the AI suggest one, test it and validate it before use.
- Active DirectoryGive the AI Assistant and pre-diagnostics read access to Active Directory, through an agent on a member server, and choose which attributes are visible.
- Ticket pre-diagnosticsFor every new ticket, FirstSI checks the account, the computer, the other tickets and whatever the request type calls for, then adds a private note and suggests a category.
- Customer AI and guidelinesChoose the AI model (the platform's or your own gateway) and give it your context through versioned guidelines.
- WAN gateway: site lines and boxesConnect the tool that reads your carriers' customer portals, so you can check a mobile line or a site's box from a ticket or the assistant.
- 3CX phone systemConnect the 3CX phone system read-only to see where an extension's calls go, monitor the trunks and the backup, and pre-diagnose telephony tickets.
API and integrations
Public API, MCP server, tokens and full reference.
- Getting started with the APIWhat the public API covers, how to call it, and what its responses look like.
- API tokensCreate a token, use it, see what it has read, revoke it.
- Pagination, errors and limitsWalk through a long list, read an error code, stay under the rate limit.
- MCP serverConnect Claude, ChatGPT, Copilot or any MCP-compatible assistant to FirstSI's data.
- Integration examplesReady-to-adapt examples in PowerShell, Python and curl: ticketing, monitoring, remote diagnostics.
- Token scopesWhat each scope allows.
- API referenceEvery route of public API v1.7.0, with its parameters.
- MCP toolsThe 58 tools of the MCP server, by scope.
Troubleshooting
Frequently asked questions and step-by-step checks.
- An agent doesn't show up or stays offlineWhat to check, in order, when an agent does not register, goes offline or stops sending data.
- I can't sign inCredentials rejected, too many attempts, two-factor code refused, SSO failing, repeated sign-outs.
- Frequently asked questionsShort answers to the questions that come up often, with a link to the page that goes into detail.