Skip to content
FirstSIDocs

Discover FirstSI

Where FirstSI gets its data, and which module to open for the question you have.

FirstSI watches your IT from a single console: workstations, servers, network, firewalls, databases, security and inventory. Support uses it to understand why Teams keeps dropping for someone, operations to find out which service is down, and security to check whether a computer has contacted a malicious domain.

Agents on your network and online services feed the console; your teams open it in a browser.Your networkWorkstations and serversFirstSI agentFirewalls, Wi-Fi, SD-WANsyslog, IPFIX, SNMPIn-house applicationstickets, SQL databases, APIsSite agentrelay, connectorsFirstSI consoleencrypted HTTPSYour teamsweb browserOnline servicesMicrosoft 365Google Workspaceread-only
Agents on your network and online services feed the console; your teams open it in a browser.

Where the data comes from

SourceWhat it bringsWhere to set it up
The FirstSI agentA Windows service installed on workstations and servers. It takes measurements, collects events and sends them encrypted to the server. The same agent carries every module; you switch on the ones you need.Install the agent, Manage agents
Network equipmentSyslog and IPFIX flows from firewalls and gateways, Wi-Fi and SD-WAN controllers (UniFi, Peplink), SNMP.Firewalls and gateways, NetworkMonitor
ConnectorsYour business applications (ticketing, deployment, printing…), Microsoft 365 and Google Workspace, read-only.Connectors

The agent never runs arbitrary commands. It only does what its modules provide for (a traceroute, a header capture, a validated connector query…), and the server only talks to it over signed channels.

Which module to open

You want to know…ModulePage
Why a user gets drop-outs or slownessNetDiag (workstation network diagnostics)NetDiag
Whether a website, a port or a Windows service respondsHostMonitor (availability)HostMonitor
Who deleted a file on a shareFileMonitor (file access)FileMonitor
Who a computer talks to, and with which programNetFlow (workstation flows)Network flows, Flow explorer
What the firewall sees: denies, VPN, threatsFirewallFirewalls and gateways
Whether a computer is looking up dangerous domainsDNS MonitorDNS Monitor
The state of sites, tunnels and Wi-FiNetworkMonitorNetworkMonitor
Why a SQL database is slow and who is blocking itDBMonitorDBMonitor
Who logged on where, which accounts are at riskSI-Tracer (Windows authentication)SI-Tracer
Installed software, its vulnerabilities, licencesAssetMonitor (inventory)AssetMonitor
An attack that only shows up when sources are combinedSIEM (correlation)SIEM
Which applications depend on which serversSI-Map (application mapping)SI-Map

Three features work across the modules. The AI Assistant answers questions asked in plain language by reading your data. Ticket pre-diagnostics checks the account, the computer and anything else relevant before a technician picks up the ticket. And the public API and MCP server connect your other tools.

What you see depends on your account

Your organisation (the "customer", or tenant) has its own set of active modules, and an administrator can narrow that list further for each user. A module missing from your menu is simply not open to you. Your role (viewer, operator or administrator) decides what you can change; see Users and roles. Either way, you only ever see your own organisation's data.

Where to start

  1. Sign in, then turn on two-factor authentication.
  2. Find your way around the console: the menu, search with Ctrl+K, theme and language.
  3. If you are an administrator, go through the first settings checklist.

Source: · FirstSI Docs · updated 2026-10-10