Host Session Health Check - Diagnostics and troubleshooting guide

To receive a detailed host diagnostic report, create a host support/log file bundle and then submit this bundle to the PCoIP health check  tool.  Once the files are submitted, it will take 5-10 minutes to produce a detailed report.  The report will be sent to your registered e-mail address.  

The host session health check is compatible with HP Anyware Standard Agent and the HP Anyware Graphic Agent.  Sequence diagrams that provide details on the message exchanged are described here.


Host Session Diagnostics Summary


Initiate Session
Session Authentication   
Resource Allocation
Prepare Host 

No Response from RADIUS Server


  • the time that the client starts to initiate a session
  • the results of the user authentication validation
  • the client or broker that is attempting a connect
  • is the host ready for the connection
  • the results of the user authentication validation

Checkout license
Accept Payload
Disconnect session  

Monitor Power Saving mode  

Mac Accessibility Permissions

Mac Screen Recording permissions

Mac Local Network Permissions

PCoIP Cloud License Configuration - Certificate issue 

PCoIP Cloud License Configuration - Grace period Issue


  • was the host able to get a license?
  • the time that the PCoIP session was established
  • the time and reason for a session disconnect
  • PCoIP session is experiencing connection issues
  • If accessibility permission is not granted
  • If screen recording permission is not granted
  • if local network permission is not granted
  • SSL peer certificate or SSH remote key was not OK
  • Could not communicate with license Server


Host Session Diagnostics Details

Initiate session ("Hello" and  "Hello-resp")

Shows when a session establishment is initiated.   The diagnostic returns:

Pass:Host has accepted a session initialization request.    

Data Collected:

Received hello command!

Implementation Details:


This diagnostic is checked at pre-session phase.  

Implementation Steps:

  • Step 1:   Find the "Hello" message being sent out. See log pattern (a)

Time Period:

  • The diagnostic starts time and end time is associated with Step 1. 

Example (a) Hello Message

LVL:2 RC:   0          AGENT :   Received hello command!


Session authentication ("authenticate" and "authenticate-resp")

Shows the results of the host session authentication phase.     The diagnostic returns:

Pass:Host was able to successfully authenticate the user on the host  
Fail:Host was unable to successfully authenticate the user on the host  

Data Collected:

Received authenticate-password command. |
Failed to authenticate user

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy

Authenticate was not successful

  • Password and username could not be validated

If the authenticate message could not be validated on the host itself.  Either the password and username were typed in incorrectly or the Active Directory system is not configured for the username/password combination.  

  1. Ensure the username, password and domain name is correct.
  2. Ensure the AD info does contain the user information.

Authenticate response timed out 

  • Unable to communicate with the AD

The authentication systems are not setup correctly, or the authentication check took to long to complete.

  • Ensure the user information is part of the AD domain identified in the test results.
  • Ensure that the user information can be accessed in less than 2 seconds.

Implementation Details:


This diagnostic is checked at pre-session phase.  

Implementation Steps:

  • Step 1:   Find the "Authenticate" message being received by the host. See log pattern (a). 
  • Step 2:   Find the "Authenticate" message being processed by the host.  See log pattern that shows success (b) or failure (c)
  • Timeout:  Step 2 must be within 5 seconds of Step 1.  

Time Period:

  • The diagnostic starts time is associated with Step 1. 
  • The end time is associated with Step 2.    

If the authenticate steps fails, then the authentication systems are not setup correctly, or the authentication check took to long to complete on either the connection manager or the remote host.

Example (a)  Authenticate Message received.

LVL:2 RC:   0          AGENT : Received authenticate-password command

Example (b)  Authenticate Message processed.

LVL:2 RC:   0          AGENT : Received allocate-resource command.

Example (c) authenticate Message did not succeed 

LVL:1 RC:-500           AGENT :Failed to get SID for user t*****1
LVL:1 RC:1326           AGENT :LogonUser failed: username: t*****1, domain: t*****a
LVL:2 RC:   0           AGENT :Failed to authenticate user 't*****1' with domain 't*****a'


Resource Allocation

Shows if the session that is being requested is a brokered connection or a direct connection.  The diagnostic returns:

Pass:Session is proceeding
Fail:Allocate-resource was not received. 

Data Collected:

Received get-resource-list command; Received allocate-resource command.

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy
Allocate resource was not received on the host. If the allocate resource was not received then the problem is on the the connection manager.

Run a health check on the connection manager to see if that is the problem.
See Connection Manager Session Health Check - Diagnostics and troubleshooting guide

Implementation Details:


This diagnostic is checked at pre-session phase.  

Implementation Steps:

  • Step 1:   Find the "get-resource-list" message. See log pattern (a). 
  • Step 2:   Find the "Allocate-Resource" message.  See log pattern (a) 
  • If both step1 and 2 find the expected message then it is a "direct connect" session.
  • If the get-resource-list is not found but an allocate-response message is found, then it is a "brokered" session.
  • If a get-resource-list is found and a allocate-response message is not found, then the diagnostic should be marked as a Failed.
  • Timeout:  Step 2 must be within 5 seconds of Step 1.  

Time Period:

  • The diagnostic starts time is associated with Step 1. 
  • The end time is associated with Step 2.    

If the authenticate steps fails, then the authentication systems are not setup correctly, or the authentication check took to long to complete on either the connection manager or the remote host.

Example (a) get-resource-list Message

LVL:2 RC:   0          AGENT :   Received get-resource-list command.

Example (b) allocate-resource command Message

LVL:2 RC:   0          AGENT :   Received allocate-resource command.


Prepare Host ("Allocate-resource" followed by a Starting PCoIP session indications)

Shows if the host is prepared to accept the connection.   The diagnostic returns:

Pass:Host is finished preparing for the connection.
Fail:Host is not ready for the connection.

Data Collected:

Received get-resource-list command; Starting PCoIP session. 

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy
Host is not ready for the connection. TBD

Implementation Details:


This diagnostic is checked at pre-session phase.  

Implementation Steps:

  • Step 1:   Find the "Allocate-Resource" message.  See log pattern (a) 
  • Step 2:   Find the "PCoIP Session Started" message.  See log pattern (b) 
  • Timeout:  Step 2 must be within 5 seconds of Step 1.  

Time Period:

  • The diagnostic starts time is associated with Step 1. 
  • The end time is associated with Step 2.    

Example (a) allocate-resource command Message

LVL:2 RC:   0          AGENT :   Received allocate-resource command.

Example (b) allocate-resource response Message

LVL:2 RC:   0          AGENT :   Starting PCoIP session. 


No Response from RADIUS Server

Shows if the client is failed to establish a the connection.   The diagnostic returns:

Fail:No Response from RADIUS Server

Data Collected:

LVL:2 RC:   0          BROKER :XML:       <result-str>Timeout: No Response from RADIUS Server.</result-str>

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy
Improper configuration of MFA extension on the RADIUS server

Reconfiguration of the MFA extension on the RADIUS server is required

Reference link: AWC Configure MFA

Checkout license ("checkout-license", "checkout-license-resp")

Shows if a license was successfully acquired for the session.  The diagnostic returns:

Pass:License acquired.
Fail:License not acquired.

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy

Licensing has not been configured

Could not launch a remote
session because there are no configured license servers

The agent can be configured to use either Cloud Licensing or a local License server. 

If you are using Cloud licensing, the each agent needs to be registered once the agent has been installed.  

If you are using a local license server, then the Connection Manager needs to be configured to point each agent at the license server

Licensing server could not be reached

Getting license failed: Could not send message to FNE license server

Is using the cloud based licensing service, check the following:

  1. Does your PCoIP Agent on the remote host have access to the internet?
  2. If using a proxy, is it setup correctly?
  3. Is your anti-virus software blocking access to
  4. Is your firewall blocking access to
  5. Do you need to white list the flexera IP addresses?  See What services need to be available for Cloud Licensing to work? for services that will need to be whitelisted.
  6. Make sure that the licensing service is up.   See How can I check if my Cloud or Local license server is healthy?

If using a local license server, check the following:

  1. Can you agent communicate directly with the license server
  2. Is the license server health check successful?  See How can I check if my Cloud or Local license server is healthy?

No available licenses 

Could not launch a remote session
because no software licenses are available on your cloud license server (

The system was able to communicate with the license server however no licenses were found.  Verify that you have installed enough licenses to meet your ongoing need.  See here for an article on how to determine if you have enough licenses licenses.

Implementation Details:


This diagnostic is checked at session phase.  

Implementation Steps:

  • Step 1:   Find the "license acquired" message.  See log pattern (a) or (b)

Time Period:

  • The diagnostic starts time is associated with Step 1. 
  • The end time is associated with Step 1.   

Example (a) of a successful license acquisition when using the Cloud licensing service. 

The XXXXXXXXX will be your license server id that is located in the cloud. The log events are found the pcoip_agent log:

LVL:2 RC:   0           AGENT :License acquired; source:; time: 2.88 s; origin: registration; remaining: 165 days;

Example (b) of a successful license acquisition when using a local license server.  

The log events are found the pcoip_agent log:

LVL:2 RC:   0           AGENT :License acquired; source:; time: 0.70 s; origin: local-settings; remaining: 290 days;

Example (c) of a unsuccessful license acquisition when licensing not configured.    

The log events are found the pcoip_agent log:

LVL:2 RC:   0           AGENT :Could not launch a remote session because there are no configured license servers
LVL:2 RC:   0           AGENT :License denied

Example (d) error logs

: Powershell command stderr: Cloud License Server: fail, no licenses were available from ''; No license available.; 

Example (e) if licensing is configured to use either Cloud or Local Licenses but no licenses are found. 

The entry will be found in the control panel log.

: Powershell command stderr: Cloud License Server: fail, no licenses were available from ''; No license available.; 


Accept Payload 

Shows the result of the client/host establishing the TCP/UDP connection over port 4172.  The diagnostic returns: 

Pass:Client/Host were able to communicate over port 4172 on both UDP and TCP
Fail:Client/Host were not able to communicate over port 4172 on both UDP and TCP

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy
Port 4172 is blockedIf the session could not be established.   Port 4172 is blocked for either UDP or TCP traffic.  The traffic may be blocked on host or client or more likely due to a a firewall setting on your network.

Implementation Details:


This diagnostic is checked at session phase.  

Implementation Steps:

  • Step 1:   Find "start session" item.  See log pattern (a)
  • Step 2:   Find the TCP message.  See log pattern (b)
  • Step 3:   Find the UDP message.  See log pattern (c)
  • Timeout:  Step 3 must be within 5 seconds of Step 1.  

Time Period:

  • The diagnostic starts time is associated with Step 1. 
  • The end time is associated with Step 3.   

Example (a) Item to look for to start the accept Payload diagnostic. 

LVL:2 RC:   0           AGENT :Starting PCoIP session.

Example (b) TCP-Handshake response received

LVL:2 RC:   0           SCNET :(scnet_open_accepted_socket): Server accepting connection from
LVL:2 RC:   0           SCNET :(scnet_open_accepted_socket): Server connecting on address

Example (c) UDP-Invite responses received

LVL:1 RC:   0           AGENT :transition from CONNECTING --(CONNECTION_COMPLETE [102])--> CONNECTED


Disconnect session

Shows when and why a host disconnects from a PCoIP session.   The note provided will explain how to interpret the disconnect cause.

Note:Disconnection are normal events that are usually initiated by the user of the client.  Disconnects can happen due to the user requesting a disconnect or due to a remote host powering down or the network disconnecting.  This diagnostic will provide a reason code.  To read more about different disconnect causes, refer to Meaning of disconnect causes

Data Collected:

Cause: X

Implementation Details:


This diagnostic is checked during the session phase.  

Implementation Steps:

  • Step 1:   Find the disconnect message. See log pattern (a)

Time Period:

  • The diagnostic starts time and end time is associated with the log found in Step 1.

When a PCoIP session disconnects, it is logged so that any spontaneous disconnects can be addressed and fixed.  The diagnostic will provide a note on how to analyze the disconnection cause

Example (a) Disconnect Message (Host)

LVL:2 RC:   0 TBD


Monitor Power Saving mode 

Indicates whether power saving mode for the weather monitor is enabled or disabled 

Data Collected:

Monitor power saving mode status

Implementation Details:


This diagnostic is checked at session phase.  

Implementation Steps:

  • Step 1:   Find the "Monitor power saving mode" status message being sent out. See log pattern (a)

Time Period:

  • The diagnostic starts time and end time is associated with Step 1. 

Example (a) Monitor power saving mode status message

 LVL:2 RC:   0     SERVER :>>>>> Monitor power saving setting is changing

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy


Monitor power saving mode is enabled.  PCoIP session may get disconnected when monitor goes into sleep state

What do I need to know about power management?

Hosts with Windows power management enabled may drop PCoIP connections when turning off displays or going to sleep. If this behavior is undesirable, these Windows power management features should be turned off.

To disable Windows power management features:

  1. From the Windows Control Panel, open Power Options.
  2. Click Change plan settings next to the enabled power plan
  3. Select Never from the drop-down list for Turn off the display
  4. Select Never in the drop-down list for Put the computer to sleep
  5. Click Save changes.
Reference URL: what-do-i-need-to-know-about-power-management


Mac Accessibility Permissions

Displays instructions on how to configure accessibility settings in mac devices

Fail:Failed to initialize input devices

Data Collected:

LVL:1 RC:-500          SERVER :start server: Failed to initialize mouse and keyboard input. Check 'Accessibility' permission is granted in System Preferences > Security & Privacy > Privacy

Corrective Actions (if diagnostic does not pass) 

Root CauseRemedy
  • Unable to create HID device
  • Input driver setup failed

Ensure that the 'Accessibility' permission is enabled in System Preferences > Security & Privacy > Privacy

Reference URL:  Confirm that the privacy permissions are turned on

Mac Screen Recording Permissions

Displays instructions on how to configure accessibility screen recording settings in mac devices

Fail:Failed to start display stream

Data Collected:

 LVL:0 RC:-500    VIDEO_DRIVER :display stream video head 0x7fb902176270: Display stream creation failure. Check "Screen Recording" permission is granted to Anyware Agent Helper in System Preferences > Privacy & Security > Privacy 
LVL:1 RC:-500    IMG_FRONTEND :<FE_ERROR_TRACE> (0x70000e670000): Failed to start display stream, Check "Screen Recording" permission is granted to Anyware Agent Helper in System Preferences > Privacy & Security > Privacy

Corrective Actions (if diagnostic does not pass) 

Root CauseRemedy
Screen capture error

Check "Screen Recording" permission is granted to Anyware Agent Helper in System Preferences > Privacy & Security > Privacy

Reference URL:  Confirm that the privacy permissions are turned on

Mac Local Network Permissions

Displays instructions on how to configure Local network settings in mac devices

Fail:Unable to establish session

Data Collected:

LVL:2 RC:  0  AGENT :ConnectionClosed message received (22) 
LVL:2 RC:  0  AGENT :monitor thread: connection_closed: SOFT - ConnectionClosed due to PCOIP_AGENT_CLOSE_CODE_NETWORK_INTERRUPTION(3):(0)

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy











Local Network error

Confirm that the privacy permissions are turned on
On the remote machine, log in using the account that will host PCoIP connections and check that the following permissions are granted on the remote machine:

  1. Open System Settings > Privacy & Security, and select Local Network from the list  options.

  2. Under Allow the apps below to control your computer, confirm that Local Network is turned on for Anyware Agent Helper.

  3. If Local Network is not turned on for Anyware Agent Helper, turn it on. This is how the Local Network screen will look:








PCoIP Cloud License Configuration - Certificate issue 

Shows if the host is prepared to accept the connection.   The diagnostic returns:

Pass:License configured successfully
Fail:License configuration failed

Data Collected:

<ERROR>: Powershell command stderr: Error executing command, list licenses, cause: Could not send message to FNE license server. [1,7e7,9,1[74000008,3c,100601cb]] Generic communications error. 
[1,7e7,9,1[75000001,60,3001014c]] General data transfer failure. SSL peer certificate or SSH remote key was not OK 

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy
SSL peer certificate or SSH remote key was not OK

•    You need to install the new certificate ("Amazon Root CA 1-4") on your OS. 
•    If you need any help on updating your certificate, please raise a support case at

More info:


PCoIP Cloud License Configuration - Grace period Issue 

Shows if the host is prepared to accept the connection.   The diagnostic returns:

Pass:License configured successfully
Fail:License configuration failed

Data Collected:

<INFO >: Grace period expires in 0 day(s).
<DEBUG>: License status text: Your grace period ends on 11 February 2025.
<ERROR>: Powershell command stderr: Cloud License Server: fail, could not communicate with '', ensure it is reachable from your system, in grace period which expires in 0 days 

Corrective Actions (if diagnostic does not pass)

Root CauseRemedy
Could not communicate with license Server

Verify the license grace period and renew the license.

  • Example:
    • PCoIP License grace period expires in 7 day(s).
    • License status text: Your grace period ends on 19 February 2025.

Refer URL: What does "Could not send message to FNE license server" mean?