TROUBLESHOOTING / SENTINELONE / ENDPOINT

SentinelOne agent
offline

A layered diagnostic path for endpoints that stop reporting to the SentinelOne management console.

01 / Confirm the symptom

Record the endpoint hostname, agent version, operating system, last-seen time and whether the device is online. Compare the console state with the endpoint's actual connectivity before changing policy.

02 / Work the layers

01OS health
02Agent service
03DNS
04HTTPS path
05Console state

03 / Evidence checklist

  1. Endpoint time and hostname.
  2. Agent service/process state.
  3. DNS resolution from the endpoint.
  4. Proxy, firewall or TLS inspection evidence.
  5. Agent logs and recent errors.
  6. Console last-seen and policy state.

04 / Isolate the fault

If the agent is healthy locally but remains stale in the console, focus on the network path, proxy configuration, certificate/TLS interception and destination reachability. If the endpoint cannot resolve or reach required destinations, fix the network dependency first.

05 / Remediate safely

Prefer restoring the intended communication path over reinstalling the agent immediately. Preserve logs before destructive changes. After remediation, verify fresh telemetry and a new console heartbeat.

Verification

Close the incident only after the endpoint reports normally and the management console shows current state—not merely because the local service is running.