SentinelOne agent
offline
A layered diagnostic path for endpoints that stop reporting to the SentinelOne management console.
01 / Confirm the symptom
Record the endpoint hostname, agent version, operating system, last-seen time and whether the device is online. Compare the console state with the endpoint's actual connectivity before changing policy.
02 / Work the layers
03 / Evidence checklist
- Endpoint time and hostname.
- Agent service/process state.
- DNS resolution from the endpoint.
- Proxy, firewall or TLS inspection evidence.
- Agent logs and recent errors.
- Console last-seen and policy state.
04 / Isolate the fault
If the agent is healthy locally but remains stale in the console, focus on the network path, proxy configuration, certificate/TLS interception and destination reachability. If the endpoint cannot resolve or reach required destinations, fix the network dependency first.
05 / Remediate safely
Prefer restoring the intended communication path over reinstalling the agent immediately. Preserve logs before destructive changes. After remediation, verify fresh telemetry and a new console heartbeat.
Close the incident only after the endpoint reports normally and the management console shows current state—not merely because the local service is running.