An agent doesn't show up or stays offline
What to check, in order, when an agent does not register, goes offline or stops sending data.
The console shows an agent as Online when it has checked in during the last 5 minutes. If it doesn't, go through these checks in order: each one rules out a cause.
1. Is the service running?
On the machine, open Services (services.msc). First SI - FSI Agent must be Running, with an Automatic startup type.
Get-Service | Where-Object DisplayName -like "First SI*"If it is stopped, start it. If it stops again straight away, jump to step 4 and read the log.
2. Can the machine reach the server?
The agent talks to the server over HTTPS, usually on port 443.
Test-NetConnection console.example.com -Port 443If you get TcpTestSucceeded : False, a firewall or a proxy is in the way. For a network without direct access, set up egress through a relay or proxy.
3. Did the installation have the right values?
SERVERURL must be the exact console address, starting with https://. APIKEY must be the current registration key, the one shown in Settings → Organization: if someone has regenerated it since, the old one can no longer register an agent.
These values are only read at the first installation. To fix them, uninstall and reinstall with the correct command line (Install the agent).
4. What does the agent log say?
The log lives in the logs folder of the installation folder (C:\Program Files\First SI\FSI Agent\logs). Look at the most recent errors. A 401 means the server rejects the key. A timeout points to the network. A rejected certificate usually means a proxy is inspecting HTTPS.
5. Has an antivirus blocked it?
The agent reads system information (connection tables, processes, event logs), which can make an antivirus suspicious. By default the MSI adds a Windows Defender exclusion (DEFENDEREXCLUSION=true). With another antivirus, exclude the installation folder (Program Files\First SI\FSI Agent) and the agent process yourself.
The agent is online, but a module sends nothing
First check that the module is actually enabled on the agent (gear button on its card in FSI Agents). After that, it depends on the module:
| Module | What to check |
|---|---|
| FileMonitor | Are Windows auditing and the SACLs in place? See FileMonitor |
| SI-Tracer | Is the agent on a domain controller? |
| DBMonitor | Is the instance declared, with read access to the system views? |
| Collector | Are the devices declared with the right sending address? See Firewall |
| Directory | Is the agent on a domain member server, not on a domain controller? See Directory |
If every agent at the same site goes offline at once, the problem is more likely the site's network (link down, tunnel down) than the agents. Have a look at NetworkMonitor.
Source: · FirstSI Docs · updated 2026-10-10