Skip to content
FirstSIDocs

Install the agent

Download the MSI, choose the modules, install by hand or at scale, check it works, uninstall.

The FirstSI agent is a Windows service (Windows 10 and 11, Windows Server) that carries every module. You install it once; after that, modules are switched on or off from the console without reinstalling.

Download

In FSI Agents (#/fsi-agents), the Download button, reserved for administrators, offers two packages: Download (.msi) for Windows x64, the usual case, and Download ARM64 (.msi) for ARM-based PCs (recent Surface Pro, Snapdragon…).

Both the MSI and the executable are signed. Windows therefore shows the publisher, and remote updates check the signature before installing anything.

The three values you need

ValueWhere to find it
Server address (SERVERURL)Your console's address, for example https://console.example.com
Registration key (APIKEY)Settings → Organization → API Key (administrators)
Signing secret (HMACSECRET)Supplied with your customer account

Install by hand

Double-click the MSI and follow the wizard. If you want to choose the modules at install time, the command line below is easier.

Silent install (mass deployment)

Silent install (example)
msiexec /i FSIAgent.msi /qn ^
  SERVERURL="https://console.example.com" APIKEY="<customer key>" HMACSECRET="<supplied secret>" ^
  NETDIAG=true NETFLOW=true ASSETMONITOR=true

Always pass SERVERURL, APIKEY and HMACSECRET on the command line. The same command works in a GPO (startup script), Intune, SCCM, Toems or any deployment tool.

Installer properties

PropertyDefaultEffect
NETDIAGfalseWorkstation network diagnostics (NetDiag)
NETFLOWfalseNetwork flows and DNS queries of the computer (Network flows)
ASSETMONITORfalseSoftware and hardware inventory (AssetMonitor)
FILEMONITORfalseFile access auditing, for file servers (FileMonitor)
HOSTMONITORfalseAvailability checks run by the agent (HostMonitor)
NETWORKMONITORfalseSNMP, ping and network discovery (NetworkMonitor)
DBMONITORfalseSQL Server and MariaDB performance (DBMonitor)
SITRACERfalseWindows authentication, to install on domain controllers (SI-Tracer)
FILEEVENTSfalseNetDiag: files opened by applications (sensitive option)
RELAISemptyEgress gateways (FirstSI relay or proxy), separated by ;. See Network egress
RELAISDIRECTtruefalse forbids falling back to a direct connection
DEFENDEREXCLUSIONtrueAdds a Windows Defender exclusion for the agent's folder and process

The Collector (syslog and IPFIX) and Directory (Active Directory, connectors) modules have no property. You turn them on from the console, on the agent of your choice.

These properties only count at the first installation: an update leaves the configuration file in place. To change the modules of an agent that is already installed, use the gear button on its card in FSI Agents.

Check that the agent is online

Within a minute, the machine shows up in FSI Agents as Online, meaning it has checked in during the last 5 minutes. On the machine itself, the First SI - FSI Agent service must be running (automatic start, system account). After an abnormal stop it restarts on its own after 60 s, up to 3 times a day. The first data reaches the screens of the enabled modules a few minutes later.

If nothing appears, see An agent doesn't show up or stays offline.

Isolated network or mandatory proxy

A computer without Internet access can go through another FirstSI agent (a relay) or through the company proxy. For the first installation, it has to be told which gateway to use:

Install behind a relay
msiexec /i FSIAgent.msi /qn SERVERURL="https://console.example.com" APIKEY="<key>" HMACSECRET="<secret>" ^
  NETDIAG=true RELAIS="relay1.example.local:3129;relay2.example.local:3129"

The rest is set up in the console afterwards; see Agent network egress.

Uninstall

Go to Windows Settings → Apps (or Programs and Features) and remove "First SI - FSI Agent". Silently: msiexec /x FSIAgent.msi /qn.

Uninstalling stops the service, deletes the agent's data and log folders and its registry key, and removes the Defender exclusion if it had added one. The machine stays listed in the console until you delete it in FSI Agents.

Source: · FirstSI Docs · updated 2026-10-10