Table of Contents

ZEDEDA Edge View

Edge View is the EVE-OS remote-access and troubleshooting subsystem. It lets you run device queries, search logs, and tunnel TCP services (SSH, VNC, HTTP, OPC-UA) from your laptop shell as if you were logged in locally, without opening any inbound port on the edge node.

Two pieces are involved:

Both the device and the laptop connect outbound to a Dispatcher (an API endpoint in the ZEDEDA cloud). All session traffic is TLS-encrypted and each message is authenticated/encrypted with a per-session nonce, so even a compromised dispatcher cannot read or modify the relay traffic.

See also: logs for real-time log retrieval with Edge View.

1. Enabling a Session (ZedControl)

Edge View is enabled per device from the controller. The session and its access policy are part of the device configuration; a controller-signed JWT is issued when the session is enabled, and the device verifies it. When the JWT expires, the session to the dispatcher is torn down.

Steps:

The Remote Access tab also exposes:

Edge View Configuration (from the Policy tab):

2. Running the Client Script

The client is a docker run wrapper, so Docker is required on the laptop (Docker Desktop + WSL2 on Windows; native Docker on macOS/Linux).

Make it executable:

chmod +x run.TF-OL-CL250-1.1782606003.edgeview.sh

Run with no arguments to view the active session and print the connect banner:

./run.TF-OL-CL250-1.1782606003.edgeview.sh
Edgeview is in multi-instance mode, use '-inst 1-3', try '-inst 1' here
xxxxxxx-HV665W34HG-inst-1 connecting to wss://zedcloud.gmwtus.zededa.net/api/v1/edge-view
connect success to websocket server
Client endpoint IP: 73.237.22.19
Device IPs: [192.168.2.30]; Endpoint IP 73.237.22.18
  UUID: f06d4baa-a5f2-4454-abce-7899fe1ec3fe
  Device: TF-OL-CL250-1, Enterprise: CSA-DEMOS-4316
  Controller: zedcloud.gmwtus.zededa.net
  EVE-OS release 17.0.0-rc2-kvm-amd64, IMGA
  Edge-View Ver: 0.8.8, JWT expires at 2026-06-28T00:20:03Z
  2026-06-27T19:24:09Z(UTC), uptime 3185 (sec) = 0 days

Multi-instance mode

When the controller enables more than one connection, the session is multi-instance. Every command must carry -inst <num> in the range shown in the banner (here 1-3):

./run.TF-OL-CL250-1.1782606003.edgeview.sh -inst 1 app

In the command reference below, -inst <num> is omitted for brevity; insert it on every call when the session is multi-instance.

Help

-h or -help prints the full query list. Per-command help is <cmd> -h:

./run.TF-OL-CL250-1.1782606003.edgeview.sh -inst 1 flow -h
flow[/<some pattern>] - display ip flow information in the kernel search pattern
  e.g. flow/sport=53 -- display all ip flow matching source port 53
       flow/10.1.0.2 -- display all ip flow matching ip address 10.1.0.2

3. Network Commands

Query group: [acl app arp connectivity flow if mdns nslookup ping route socket speed tcp tcpdump trace url wireless]

Examples:

./run.TF-OL-CL250-1.1782606003.edgeview.sh tcpdump/ethø/'port 443'

./run.TF-OL-CL250-1.1782606003.edgeview.sh route

./run.TF-OL-CL250-1.1782606003.edgeview.sh connectivity
./run.TF-OL-CL250-1.1782606003.edgeview.sh socket


4. System Commands

Query group: [configitem cat cp datastore dmesg download du hw lastreboot ls model newlog pci pprof ps cipher usb tar techsupport top volume]

Example - device memory snapshot:

 === System: <app> ===

 - device memory
Total = 7624 MiB
Available = 6920 MiB
Used = 463 MiB
Used Percent = 6.076
Free = 6568 MiB

Some logs never reach the controller (app logs set to “do not upload”), or the enterprise has no cloud log search. Edge View searches the on-device logs directly.

log/<search> [-time <start>-<end>] [-json] [-type <app|dev|all>] [-line <n>]

Bulk download (no search string) - reserved word copy-logfiles, max 30-minute span:

./run.TF-OL-CL250-1.1782606003.edgeview.sh -inst 1 log/copy-logfiles

Files land in the container's /download. The client mounts laptop /tmp/download to container /download, so they appear locally under /tmp/download/logfiles-<timestamp>/ as merged, time-ordered dev.log.txt and app.<uuid>.log.txt.

6. TCP Channel (Tunnels)

The tcp command is the most powerful one. It builds a TCP relay from your laptop, through the dispatcher, into the device, and on to apps or external hosts. It works across NAT, firewalls, and proxies. Multiple channels can run at once.

tcp/ip:port[/ip:port...][/proxy[@dns-ip]]

SSH into an app

VNC into a VM app console

Other app TCP services

Dom0 / external hosts / HTTPS proxy

7. Collect Info, TechSupport, File Transfer

These three deposit files into the container /download (laptop /tmp/download):

8. Pub/Sub Commands

For users with EVE internals knowledge. EVE microservices publish state under /run/<service>/; pub reads it back.

Services: [baseosmgr domainmgr downloader edgeview global loguploader msrv newlogd nim nodeagent tpmmgr vaultmgr volumemgr watcher zedagent zedclient zedkube zedmanager zedrouter zfsmanager]

9. Security Notes

Sources