Discover FirstSI
Where FirstSI gets its data, and which module to open for the question you have.
FirstSI watches your IT from a single console: workstations, servers, network, firewalls, databases, security and inventory. Support uses it to understand why Teams keeps dropping for someone, operations to find out which service is down, and security to check whether a computer has contacted a malicious domain.
Where the data comes from
| Source | What it brings | Where to set it up |
|---|---|---|
| The FirstSI agent | A Windows service installed on workstations and servers. It takes measurements, collects events and sends them encrypted to the server. The same agent carries every module; you switch on the ones you need. | Install the agent, Manage agents |
| Network equipment | Syslog and IPFIX flows from firewalls and gateways, Wi-Fi and SD-WAN controllers (UniFi, Peplink), SNMP. | Firewalls and gateways, NetworkMonitor |
| Connectors | Your business applications (ticketing, deployment, printing…), Microsoft 365 and Google Workspace, read-only. | Connectors |
The agent never runs arbitrary commands. It only does what its modules provide for (a traceroute, a header capture, a validated connector query…), and the server only talks to it over signed channels.
Which module to open
| You want to know… | Module | Page |
|---|---|---|
| Why a user gets drop-outs or slowness | NetDiag (workstation network diagnostics) | NetDiag |
| Whether a website, a port or a Windows service responds | HostMonitor (availability) | HostMonitor |
| Who deleted a file on a share | FileMonitor (file access) | FileMonitor |
| Who a computer talks to, and with which program | NetFlow (workstation flows) | Network flows, Flow explorer |
| What the firewall sees: denies, VPN, threats | Firewall | Firewalls and gateways |
| Whether a computer is looking up dangerous domains | DNS Monitor | DNS Monitor |
| The state of sites, tunnels and Wi-Fi | NetworkMonitor | NetworkMonitor |
| Why a SQL database is slow and who is blocking it | DBMonitor | DBMonitor |
| Who logged on where, which accounts are at risk | SI-Tracer (Windows authentication) | SI-Tracer |
| Installed software, its vulnerabilities, licences | AssetMonitor (inventory) | AssetMonitor |
| An attack that only shows up when sources are combined | SIEM (correlation) | SIEM |
| Which applications depend on which servers | SI-Map (application mapping) | SI-Map |
Three features work across the modules. The AI Assistant answers questions asked in plain language by reading your data. Ticket pre-diagnostics checks the account, the computer and anything else relevant before a technician picks up the ticket. And the public API and MCP server connect your other tools.
What you see depends on your account
Your organisation (the "customer", or tenant) has its own set of active modules, and an administrator can narrow that list further for each user. A module missing from your menu is simply not open to you. Your role (viewer, operator or administrator) decides what you can change; see Users and roles. Either way, you only ever see your own organisation's data.
Where to start
- Sign in, then turn on two-factor authentication.
- Find your way around the console: the menu, search with Ctrl+K, theme and language.
- If you are an administrator, go through the first settings checklist.
Source: · FirstSI Docs · updated 2026-10-10