A few words you'll meet throughout:
- PLC — the industrial computer inside the machine's control cabinet that actually runs the machine. LineKeeper talks to it over the network.
- Tag — a single named value inside the PLC: a temperature, a motor speed, a counter, an on/off state. Machines typically have hundreds or thousands of tags.
- Writing a tag — sending a new value to the machine (like pressing a button or changing a setpoint on a normal operator panel).
- Collecting / recording — storing a tag's values over time so they can be charted, alarmed on and analyzed later. Nothing is recorded until you choose which tags to record.
The interface works two ways: on the device's own touchscreen, or from any browser on the same network — open http://<device-address>:5000. For longer setup sessions the browser is more comfortable; the on-device screen is small and best for day-to-day use.
1. A quick tour — where everything is
Left sidebar — the main menu:
| Tab | What's there | Who uses it |
|---|---|---|
| PLC | Connection to the machine, the full live tag table, write actions, I/O modules | Administrator (setup), technician |
| Control Panel | The operator screen: buttons, lamps, numbers — built by the wizard or by hand | Operator, daily |
| Dashboards | Charts and statistics built from recorded history | Everyone |
| Alarms | Alarm rules on recorded tags, active alarms, 90-day history | Everyone |
| Diagnose | What the device noticed on its own, the timeline of stops, what it has learned about the machine, and Ladder — the controller's own program with live values | Administrator, technician |
| Reference | Built-in fault-code tables from the vendors' manuals — look up a code or a word | Everyone |
| Settings → Recording | Recorder status, what is recorded and how | Administrator |
| Settings | Users, network, machines, notifications, backup, updates | Administrator |
Below the menu: a live counter of Tags and I/O modules on the connected machine, and a Collecting indicator — green when the recorder is running. When an update is ready, an Update available button appears here too (administrator sessions only — operators never see updates). The Logout button is at the very bottom.
Top bar, left to right:
- ☰ — hide/show the sidebar.
- Clock, and next to it the time of the last data update received from the machine.
- Theme toggle (light/dark).
- Status pill — the connection indicator: green with the machine's address when connected (e.g.
EMULATOR:0or192.168.1.10:0), Reconnecting… or Offline otherwise. Click it to open System Logs. See section 20. - When two or more machine profiles exist, a machine selector also appears here (section 12).
Signed in as Operator, the menu shows only Control Panel, Dashboards, Alarms and Reference, and every editing control is hidden — operators can watch values, use the panel, see alarms and look up a fault code, nothing else. Diagnose, like the PLC tab and Settings, is for administrators. The device's own screen opens straight onto the Control Panel; an administrator in a browser lands on the PLC tab.
2. First-time setup, step by step
What you need: the device powered on, a network connection between the device and the PLC (cable to the machine's switch, or the same plant network), and a phone or computer for the first minutes.
Step 1 — the first-boot wizard
Out of the box (and after a factory reset) the device shows a short Device setup wizard on its own screen: create the administrator password, then connect to your Wi-Fi (or skip it if you only use the wired port). An on-screen keyboard pops up for the text fields.
No screen in reach, or the device can't find a network? Within about 90 seconds it starts its own Wi-Fi hotspot, LineKeeper-XXXX (password linekeeper). Join it from a phone or laptop — the setup wizard opens by itself as a captive-portal page (if it doesn't, open http://10.42.0.1:5000/setup). The hotspot disappears once the device is on a network; it comes back whenever the device loses all connectivity.
Step 2 — open the interface
- On the device screen: it boots straight into the interface.
- From a computer or phone: open
http://<device-address>:5000in a browser. The device's current address is shown on its own screen under Settings → Wired network / Wi-Fi. On most networks the name also works:http://linekeeper-XXXX.local:5000— XXXX is the same four characters as the hotspot name, printed on the device.
Step 3 — sign in
Choose the Administrator role, enter the password you created, press Sign in (section 3).
Step 4 — connect to the machine
On the PLC tab:
- The machine profile is already selected (rename it later in Settings → Machines).
- Press Find PLCs — the device scans the network and lists the controllers it can see; tap one and the form fills itself. Or choose the Protocol by hand: EtherNet/IP (Allen-Bradley ControlLogix / CompactLogix), AB Legacy (SLC-500 / MicroLogix / PLC-5), AB Drive (PowerFlex, read-only), EtherNet/IP Device (read-only), Modbus TCP/RTU, Siemens S7 or OPC UA.
- Enter the controller's IP address and the protocol's extra fields — Slot for Logix and S7 (usually 0), rack for S7, port and unit ID for Modbus. Your electrician or the machine documentation will know.
- Press Connect.
Within seconds the full tag list appears with live values — on Logix and OPC UA the controller hands over its own tag names, and the legacy Allen-Bradley families reveal their data files (N7, B3, T4 …). Modbus and Siemens S7 carry no tag names at all, so for those you paste a short tag map first (one line per value; the form shows the format and gives names to the addresses). Tick Auto-connect so the device reconnects by itself after a restart. The last 10 connections are kept in a history list under the form.
No machine at hand? Press Emulator — the device connects to a built-in demo generator with synthetic tags so you can try every feature safely. All screenshots in this manual were taken this way.
Step 5 — get the operator panel back
If you are replacing a dead panel, go to Control Panel and press Restore control: the wizard finds the PLC, takes the old panel's project file or the PLC program if you have one (or finds the controls by watching what changes when you press them on the machine) and builds the panel for you. Details in section 6. Otherwise assemble the panel by hand — section 5.
Step 6 — choose what to record
Recording powers dashboards and alarms, and most of it needs no choosing:
- Discrete signals — every BOOL tag and I/O bit is recorded by the event recorder from the moment the controller is connected. Run signals, buttons, sensors, valve feedback: all there, nothing to tick.
- Numbers — on the first connect every numeric tag of the controller (speeds, counts, timer values, setpoints; up to 200) joins the history by itself. Recording starts as soon as they are saved.
- Recording starts by itself as soon as the device connects to the controller, and the device reconnects on every power-on. Under Settings → Recording you can prune what you do not need, add anything missing from the PLC tab (row menu ⋮ → + Add to history), and write a short description per tag ("Main pump motor current") so everyone knows what the value means. Details in section 8.
Step 7 — verify data is flowing, then build
Open Dashboards — the auto-created dashboard should show fresh values for your collected tags within a minute. If yes, recording works. Then build a dashboard from a ready-made recipe in section 10, and add an alarm or two (section 11).
Setup checklist: connected (green pill in the top bar) → tags collecting (green "Collecting" in the sidebar) → fresh values on the dashboard → auto-connect enabled → operator password set (section 14) → configuration exported (section 15).
3. Signing in and roles
- Choose your role: Operator or Administrator.
- Enter the password for that role and press Sign in.
- Operator — sees the Control Panel, Dashboards and Alarms; can press the panel's buttons and send values from its numeric fields. Cannot change anything. Stays signed in for 7 days.
- Administrator — full access: connections, recording, panels, dashboards, alarm rules, settings, users. Writes go through the per-tag unlock list. Stays signed in for 24 hours.
After five wrong passwords in a row from the same device, sign-in from it is refused for a minute.
The device's own screen needs no password. Like a hardware panel, it signs in as Operator automatically at boot, so an operator never sees a login form. Browsers on the network still need a password. An administrator can switch this off in Settings → Users & security → Operator screen without a password.
Signing in by name on the device's screen. People registered in Settings → Users & security → People sign in on the screen itself, three ways:
- Sign in button (bottom of the sidebar) → tap your name → enter your PIN on the large on-screen pad. Sign out on the same spot ends it.
- Badge: hold your badge to the USB reader — no name, no PIN. Hold your own badge again to sign out; someone else's badge switches the person at the screen.
- Access key on the rear terminals (panel models, section 18).
A signed-in person has the role the administrator gave them: an operator's name goes on every value they write; an administrator opens every setting on the screen without a password. Five wrong PINs in a row lock that name for a minute. A person who does not touch the screen is signed out after a while (8 hours for an operator, 1 hour for an administrator; adjustable in the People card) and the screen falls back to the nameless operator. When a key and a badge or PIN disagree, the higher role is in charge and both are in the shift log. None of this applies to phones and laptops — they keep the role passwords.
The Gateway online dot under the button confirms the device itself is up.
Forgot the administrator password? It can be reset from the device's service console with the included reset_password.sh utility — the new password is printed on screen. (There is no "email me a reset link": the device is fully offline by design.)
4. PLC tab — connect, watch, write
(Screenshot in section 1.)
Connection
The PLC Connection card at the top: machine profile, protocol and its fields, Connect / Disconnect, Find PLCs, Emulator, Auto-connect — as in Step 4 above. What each protocol gives you:
| Protocol | Controllers | Tag names | Writes |
|---|---|---|---|
| EtherNet/IP | Allen-Bradley ControlLogix, CompactLogix | Read from the controller, including UDTs and arrays | Yes |
| AB Legacy | SLC-500, MicroLogix; PLC-5 (experimental) | Data files discovered from the controller (N7:0, B3:0/5 …); an optional tag map adds names | Yes |
| AB Drive | PowerFlex drives (Kinetix experimental) | Built-in parameters: frequency, current, status, fault codes | No — monitor only |
| EtherNet/IP Device | Any CIP device | From a tag map | No — monitor only |
| Modbus TCP/RTU | Anything speaking Modbus — over the network, or serial (RTU) on the panel's RS-485 / RS-232 terminals or a USB adapter | From your tag map (holding/input registers, coils) | Yes |
| Siemens S7 | S7-300/400/1200/1500 (PUT/GET enabled, non-optimized DBs) | From your tag map (DB5.DBD12, MW10 …) — S7 has no tag discovery | Yes |
| OPC UA | Any OPC UA server | Browsed from the server | Yes |
Watching live values
The tag table updates twice a second:
- Search by name or filter by data type.
- ★ Star the tags you care about; "★ Favorites only" filters the table down to them. Favorites are reused across the app (Control Panel pickers, filters).
- ▼ Bits — expand an integer tag to see each of its bits individually (useful when one number packs many on/off flags). Bits can be written by clicking them.
- Structured tags (UDTs) and arrays unfold into their fields and elements.
- I/O modules — the machine's physical input/output cards, point by point. A point the module reports as faulted is flagged as such instead of showing a stale value, and a state the device cannot read is shown as unknown rather than guessed.
Sending values to the machine
Each row's actions (some behind the ⋮ menu):
- ⇄ Toggle — flip an on/off tag.
- ⏺ Momentary (Hold) — the tag is ON while you hold, OFF when you release.
- ✎ Write — type a new value for a number or text tag.
Writes reach only tags that were explicitly unlocked. The first write to a locked tag asks the administrator for a one-time unlock (operators see "ask an administrator"); tags bound to Control Panel widgets are unlocked by that binding. The unlocked list lives in Settings → Write access, where any tag can be locked again.
Tags in a safety program (Program:Safety…) or named safety* are blocked in code and can never be unlocked. This is a naming heuristic, not a safety function — LineKeeper must never be part of a safety loop regardless.
Every write and every unlock is recorded in the audit log: who, when, which tag, what value, and whether it succeeded. What a write does is entirely up to the machine's own program — LineKeeper behaves exactly like a normal operator panel.
5. Control Panel — your operator screen
This is the screen an operator uses day to day. It can be built three ways: by the Restore control wizard (section 6), by importing the old panel's project file, or by hand — no programming in any case.
Widgets
- Button (momentary) — active only while pressed, like a jog button. Releases automatically, even if the page is closed mid-press.
- Button (maintained) — press to turn on, press again to turn off.
- Indicator — a lamp that lights when a tag is on.
- Numeric display — a live number, read-only.
- Numeric input — shows the current value plus a field to send a new one (type a number, press ▶).
- Text (string) — a live text value, read-only.
- Section — a header to group widgets visually.
Under a remote control key. When an administrator has assigned a remote control key (section 19), the panel works differently in a browser that is not the device's own screen. A button sends a command only while the key is in REMOTE, you have taken control and the button's tag is on the remote control list. A momentary button then runs for as long as you hold it and is released when you let go, leave the page or lose the connection. The device's own screen works as before. With no key assigned nothing changes.
Building the panel by hand
- Press Edit mode.
- In the form: choose Type, write a Label ("Conveyor ON/OFF" reads better than a raw tag name), pick the Tag, press + Add. Tick ★ Favorites to shorten the tag list to your starred tags. Buttons take a Color: default, blue, green (start) or red (stop).
- Don't know which tag a button is? Press 👆 Find by action, then press the real control on the machine — the device watches the controller and picks out the tag that changed (section 6 explains the watch).
- Optionally give a button a separate Indicator tag — the command goes to one tag, the button's lamp reflects another (e.g. confirmation from the machine).
- Tap a widget's pencil to edit it, drag widgets to reorder, × to remove. Press View mode when done.
Importing the old panel's project
Import HMI project takes the export of the panel you are replacing — FactoryTalk View (ME/SE), View Designer, FactoryTalk Optix, TIA Portal / WinCC or Weintek EasyBuilder — and turns its buttons, indicators and numeric fields into LineKeeper widgets. Which file do I need? in the dialog says where each package keeps the export. Check tags against PLC confirms every imported tag exists on the connected controller before you accept the result.
Auto panel from the PLC program
With the controller's .L5X on the device (Diagnose → Ladder or the wizard), Edit mode → Auto panel from program builds a panel named Program (auto) with no questions asked: every control the ladder analysis proves the old screens used to write — buttons, switches, setpoints and timer / counter presets, a section for each — plus the read-only status tags the name rules are sure about. Every tile carries an auto mark, so a computed tile is never mistaken for one an engineer placed. Press the button again after a new export and that one panel is rebuilt; panels you made by hand are never touched. A name alone never arms a write: a tag the program itself writes is shown read-only, and a by-name Reset stays out.
What a tile is called. The section says the kind, so the tile says only the name — and the most readable name the program offers, in this order: the alias the old panel program used (Cups_Reset_PB, not Panel[1].10 — HMI buttons are usually bits of a word with an alias each), else the tag's description when it is short enough to be a label (a member of a structure never borrows its parent's text), else the label the imported HMI project gave the tag, else the tag itself. A unit the program knows is kept: «Fill_Time (ms)», «Good_Ctr (count)». If two descriptions would read the same, those tiles fall back to their tags. The value is always written to the real tag, which stays in the tile's tooltip together with the description.
Timer and counter arrays. A project that keeps its timers in an array (Alarm_Timers[8]) gets their presets on the panel like any scalar timer: the device polls each element's members (Alarm_Timers[3].PRE), so the tile shows the live preset and writes back to it. Arrays of a user-defined type (recipe records) are polled the same way. Members are added up to a fixed budget of extra reads per connection; elements past it are listed in Diagnose but not polled, and the connection log says how many.
Recipes and the values loaded from them. Many programs keep a table of products (Recipes[Prog_No]) and copy the selected record into the working timers and setpoints — when the product number changes, on a Load button, or every scan. Those working values are then twins of the recipe: the next load overwrites them. The auto panel (and the wizard) tell the two apart from the ladder and work the way an HMI recipe screen does:
- A Recipe section holds the recipe controls and nothing else. Select recipe shows the selected number (and the record's name when the recipe has a text field) and takes a number to select. When the program has its own recipe buttons — an HMI bit that loads the selected record, one that saves the working values into it (
Panel_Load_Recipe,Panel_Save_Recipe) — those buttons move here as Load recipe and Save to recipe and are not listed among the buttons again: Save to recipe selects the number you enter, then presses the program's button, so the program saves the whole record exactly as it always did (when selecting also loads, the tile saves into the selected record only). Without such buttons, Save to recipe writes the working values as they stand on the panel into the record you name, field by field — the tile lists what it saves and asks first. Copy recipe copies every field of one record, the name included, into another. Writes go to the real tags (Recipes[2].Fill_Time); the tiles' bindings approve those fields in every record. There is no tile per field and nothing clears a record. - The working values loaded from the record are inputs under From recipe (or Loaded values when the source is not a recipe), each saying where its number comes from — «from Recipes[Prog_No].Fill_Time when Prog_No changes». Adjust them on the machine, then keep them with Save to recipe. A value the program reloads every scan is shown read-only: typing into it would be pointless.
- A value the program loads only on a button (a recipe download) stays an ordinary input — it is still entered from the screen between downloads — and says so under the number.
A button that flips a bit shows that bit. A pushbutton the ladder reads through a one-shot into a pulse that toggles a state bit (Panel_With_Sealing_2 → ONS → Pulse_With_Sealing_2 → the toggle rung of With_Sealing_2), that latches a bit with OTL, or whose contact sits in parallel with the output's own contact (the classic start / seal-in, no one-shot needed), changes something no other rung sets — so the panel would never show whether it is on. The analysis finds such bits and puts each on the button that activates it: the tile lights when the bit is on and says ON / OFF instead of PUSH, and sits under Switches — to the operator a press that flips a state is a switch. When a button activates several bits, the latched or toggled one wins over a seal-in memory. A reset from elsewhere (the first scan, a fault) does not take the bit away from its button; a condition in series with the pulse, and a button that only clears the bit (OTU), never get it.
Lamps and readouts from the program. A bit the program sets and reads back in several places — latched, sealed in or written every scan (Work, OK_To_Test, Alarms, a station's Sealing_1) — is a machine state: the auto panel shows the twelve most-used ones under Indicators, the wizard offers them all; bookkeeping bits (Mem_, Pulse_, one-shot storage) and bits read only as part of a word are never lamps. A number named as status or feedback that no rung computes (Rotor_IndexAxis.Status.Act_Position) is a readout, shown and never entered. A value the program clamps (LES(X,0) MOV(0,X), GRT(X,15) MOV(10,X)) gets those bounds as the input's min / max — what the program lets through, not what it writes instead — and a recipe selector clamped the same way offers only those record numbers.
HMI practices the analysis understands. Buttons and switches kept as bits of a DINT word (Panel[1].15, named through aliases such as Panel_With_Sealing_2), with the word zeroed on the first scan or after the buttons were read (FLL(0, Panel[0], 3), MOV(0, Cmd_Word)) — those bits stay the screen's, momentary or maintained by how the ladder reads them. A one-shot counts only in series with the contact: a pushbutton and a selector switch that share a rung in parallel legs are told apart. A recipe copied with COP … 30 moves all thirty elements, so the recipe's fields, the loaded values and Copy recipe cover the whole record.
A program without a recipe structure gets none of this: no section is invented from a name alone.
Panels and full screen
Create multiple panels (+ Panel / Rename / Delete panel) — for example one per line section; switch them with the dropdown next to Edit mode. Full screen hides the menu and top bar and shows nothing but the tiles — the mode the device's own screen uses next to a machine. Values refresh several times per second.
An empty panel tells an operator to call the maintenance engineer and shows a QR code: the engineer scans it with a phone, opens this device, signs in and runs the wizard from there.
6. Restore control — the panel-died wizard
The wizard is the fastest way from a dead operator panel to a working one. It starts from Control Panel → Restore control (shown whenever the panel is empty) and walks through:
- Find the PLC. The device scans the network and lists every controller it sees (product name, address). Pick the machine's. If the PLC tab is already connected, this step is skipped.
- Do you have a project file? Three ways forward:
- The HMI export — the original panel's project (FactoryTalk View, View Designer, Optix, TIA Portal/WinCC, Weintek). This rebuilds the panel exactly: the same buttons, the same tags.
- The PLC program (.L5X) — a Studio 5000 export of the controller (right-click the controller → Export → .L5X). LineKeeper reads the ladder — never the controller — and works out which tags the old screens used to write: the buttons, setpoints and timer presets. Those become the panel; the timer and counter presets are listed under their own Timers heading and land in a Timers section at the bottom of the panel. A row shows the alias the old panel program used next to the real tag (
Cups_Reset_PB = Panel[1].10), and the tile is named the same way as on the auto panel (alias, short description, imported label, tag — see section 5). A recipe table the program copies from is listed as a Recipe group (Select recipe, Save to recipe, Copy recipe), and the working values it loads are listed as Loaded from the recipe — inputs the operator adjusts and then saves under a recipe number. A pushbutton that toggles or latches a bit is listed with «shows that bit»: the bit becomes the button's indicator. The same file loads the Ladder view. - No — find the controls (Logix only). The device lists likely candidates by name; for each one you can Find it by action: it learns the machine's resting state for a few seconds, then asks you to press the control on the machine within a countdown and reports the tag that changed. Press again to confirm if two presses disagree. Modbus has no tag discovery — a project file or a tag map is required there.
- Confirm the controls. Toggle on the ones that match the machine and say what each is: a running indicator, a reset/acknowledge button, a speed readout, or any other value shown as a number or an indicator.
- Build panel. The widgets land on the Control Panel, their tags start recording, and the wizard reports Control restored with the time it took. Open the panel — the operator is back in business.
Nothing in the controller is modified at any step; the wizard only reads.
7. Ladder — the PLC program, live
Diagnose → Ladder shows the controller's own logic — rungs, branches, timers, counters, real tag names and rung comments — with the live value of every operand drawn on the diagram. A technician can follow why an output is off without a Studio 5000 license and without touching the controller.
- Load a program: in Studio 5000 right-click the controller in the tree → Export… → save as .L5X, then upload it here (administrator only). The preview names the controller and processor, counts programs and routines, and — if the PLC is connected — checks the file's tags against the live controller: tags it can't find are listed and drawn grey.
- Pick a program and routine; search filters to the rungs that mention a tag ("3 of 41 rungs match"). The routine is shown whole — the page scrolls, the ladder has no scroll box of its own; rungs draw as they come into view.
- The file is a snapshot: the export date is shown, and online edits made after it are not reflected. Replace file when the program changes; Remove deletes it from the device.
- Download .L5X hands back the very file that was loaded — the device keeps a copy next to the ladder, so the program can be recovered from the box if the laptop it came from is gone. Administrator only. A program loaded before this copy was kept shows no button: load the .L5X once more to keep it.
- The view is read-only and, like the whole Diagnose tab, for administrators: the operator's menu does not show it.
Why is it off? — the program explains a signal
With a program loaded, any on/off signal can be asked why: tap the tag in the PLC tab and pick Why is it off? (or Why is it on?), press Why? on a tag card in the Ladder view, or Why? (PLC logic) on a finding in Diagnose. The device answers from the rungs, not from a guess:
- every rung that writes the signal, with whether it is powered right now;
- the conditions on the way to it, each marked ✓ met, ✗ not met or ? cannot be judged (a one-shot, a value the device does not read);
- the conditions that hold the signal in its current state are followed further — down to the physical input the logic waits for, or to a signal that nothing in the ladder writes (an HMI bit, a pushbutton, a message from another controller). Under Where it stops — what to check those end points are listed, inputs first.
- a raw address is shown together with the name the program gives it: an input declared as
B14_Cups_Lift_DownforLocal:1:I.Data.4appears as B14_Cups_Lift_DownLocal:1:I.Data.4, with the tag description on top when the export has one — the machine's own name and where the wire lands, both. - Show rung opens that rung in the Ladder view with live values.
On a finding, the explanation is first shown as recorded at that moment (the values the device saw when the signal failed to come), with a switch to the live values. Without a program the button explains that the L5X is needed — nothing else in Diagnose changes.
With the program on the device, Diagnose also tells a control problem from a mechanical one: Held off by a PLC condition (the logic is deliberately not commanding the movement — follow the tree to the input it waits for) versus The PLC did its part — the machine did not answer (the command's rung was satisfied, the output energized, the feedback never came: actuator, air, sensor, wiring). A third note, The stored program disagrees with what was recorded, means the L5X on the device is probably not the program running in the controller (an online edit, a newer export) — replace the file.
The rest of the Diagnose tab
Ladder is the fourth view of Diagnose. The other three work from what the recorder keeps (section 8) and need no program, though with one the findings say more.
The line under the view buttons is the recorder at a glance: whether it is recording, how many signals it watches, how much history it holds, whether the controller answers on time, and the stop signal — the tag that tells the device the machine is running.
- Findings — what looks wrong compared with what the device has learned: a signal in the wrong state for this step of the cycle, a movement that did not happen, the controller answering slowly. Each finding carries how sure the device is, Why the device thinks so, Where to look in order, what to check first, and — with a program loaded — Why? (PLC logic).
- Timeline — every stop and fault of the last 8 hours to 7 days. Pick one and see which signals changed around it, from 30 seconds before to 5 seconds after by default; filter by signal name or by source (tags, I/O bits, alarms), widen the window, switch to Live, or download the list as CSV. Changes caught in the same poll are shown together — the order between them is unknown. Stop signal… picks another tag when the device guessed the wrong one.
- Model — what the device knows about this equipment: how many signals it has watched and for how long, the operating modes and the repeating cycle it found, and the relations between signals (after A changes, B usually changes). The model gets better on its own every 15 minutes of running; Learn now does it at once. Teach a mechanism… gives a group of signals a name, so a finding can name the part to check.
8. Recording — history and the event recorder
Recording is what powers Dashboards, Alarms and Diagnose — and it runs by itself: the device connects to the controller on power-on, records every discrete signal, and keeps the history of every numeric tag. This page is where you check on it and prune the list.
Recording — the recorder itself: state, polls, writes, errors, database health. ▶ Start / ■ Stop are the manual override; the address it records from is taken from the controller you connect to, and auto-start on boot is on by default.
Record all discrete signals (event recorder) — on by default: every BOOL tag and discrete I/O word of the controller is recorded on change into an event ring on disk, which feeds the Diagnose tab. Event ring (MB) caps that ring — about 7–10 days on a busy machine at 1024 MB.
Collect every numeric tag automatically — on by default: the first time a controller is connected, every numeric tag it has (up to 200, plain values first, then timer/counter accumulators, array elements and presets) is added to the collection. Once the list exists the device never re-adds on its own — what you remove stays removed; Add all numeric tags brings in whatever is still missing. BOOL and I/O signals are not on this list at all: the event recorder keeps them, and the dashboard widgets read them from there.
While the event recorder runs, the history tags are read inside its batch — one PLC round-trip per cycle instead of two.
Tags for collection — per tag:
- Mode —
on_change: store a point only when the value changes (a deadband ignores tiny noise: with deadband 0.5, a change from 66.2 to 66.5 is not stored);on_interval: store every N seconds regardless of change. - Description — a plain sentence about what the tag is ("Filler tank temperature, normal 66–72"), so dashboards and alarm messages read like the machine, not the PLC program.
- Active — pause/resume recording of that tag without deleting its settings.
The recorder runs in the background with its own connection — it keeps logging when nobody is looking at the screen, and reconnects automatically after network problems.
How long data is kept: every raw point for 30 days; hourly averages for 1 year; daily averages for 5 years. This happens automatically — dashboards pick the right tier for the period you ask for.
9. Dashboards
Create any number of named dashboards (+ New / Rename / Delete) and fill them with widgets. Ready-made examples with exact settings are in section 10.
Dashboards from program
With a PLC program on the device (Diagnose → Ladder or Restore control), Edit mode → Dashboards from program lists the dashboards the program itself suggests — nothing is created until you press Add selected:
- Machine state — the state bits the program sets and reads back (the lamps the old screens showed), the most used ones as timelines, the top one as a share-of-time donut;
- Production — the figures the program computes and no screen enters: a count becomes an output / rate counter with a per-hour bar chart, a speed a number with a trend;
- Positions — values the program only reads from a drive or axis, and the positions it computes;
- Stations — … — one per shift register: a word the program shifts (
BSL/BSR) on every cycle pulse is a track of the parts through the machine, and the bits it reads are the stations that look at it. Each widget counts the cycles a part was at that station; - Alarms — the alarm bits the program latches, as timelines.
Every proposal carries a summary in plain words and, under Widgets and why, one line per widget saying which rung it comes from. Tick what makes sense; on Add selected the tags join the collection (on change) and each dashboard is created, named Program · …. Charts fill up from that moment. Pressing the button again replaces only those dashboards; the ones you made by hand are never touched. The same analysis feeds Auto panel from program and Alarm rules from program.
Adding a widget
Press Edit mode, pick a Tag, a Type (the list adapts to the tag's data type), a Period, and optionally an Aggregation; for charts and gauges you can add up to four limit lines (HH / H / L / LL), set Points (detail level, 20–200) and a color. Press + Add.
Widget types
| Widget | For | What it shows |
|---|---|---|
| Chart | numbers | The average line inside a shaded min–max band: even a spike lasting seconds shows up on a 24-hour chart as a band spike in its window. Pick an explicit aggregation (mean/min/max/…) to get a single line instead. Limit lines HH/H/L/LL are drawn dashed. |
| Number | numbers | Last value + mean for the period. |
| Gauge | numbers | A horizontal bar with colored threshold zones. |
| Table | anything | The last ~20 stored values. |
| Out-of-spec % | numbers | How much of the time the value violated its H/L limits. |
| Boolean (uptime/cycles) | on/off | ON/OFF now, uptime %, work/idle time, number of starts, cycle min/avg/max. |
| State timeline | on/off | A colored ribbon over time: green = on, gray = off. Stops are visible at a glance. |
| Donut (uptime %) | on/off | The same uptime number as the Boolean widget, as a ring. |
| Counter (output/rate) | counters | Production for the period + rate per hour. Understands counter resets (a reset to zero is not counted as negative production). |
| Bar chart (output per window) | counters | Output per hour/shift/day — set the window and number of bars. |
| Error code (top-5 / events) | fault codes | % of time without faults, the top-5 codes by duration, recent events — each code explained from the built-in fault tables when the vendor is known. |
| Sequencer (time per step) | step numbers | Average time per step and total cycle time — where the cycle spends its time. |
Periods and refresh
Pick a period per widget (real time, 15 minutes … 30 days), or override all widgets at once with Period (all widgets) — including a custom date range (two date-time pickers). Set Auto refresh (30 s / 1 min / 5 min) for a wall display; otherwise refresh manually.
Every widget can explain itself
Not sure what a widget is actually showing? In Edit mode every widget shows a row of small buttons — press ?:
It explains — for that specific tag and period — how many time windows the period is split into, which aggregations run, where the data comes from and how often it refreshes. Use it to check the widget is set up the way you intended.
Full data and CSV export
Next to it, the 📋 button opens the complete list of stored points behind the widget, with Download CSV for reports and spreadsheets:
10. Dashboard examples (recipes)
Three dashboards that cover the most common needs. Tag names are from the demo bottling line — substitute your own.
Recipe 1 — Production for the shift
Answers: how much did we make, at what rate, how many rejects, per hour?
Needs a cumulative production counter recorded (e.g. Good_Parts), ideally a reject counter and a speed value.
| # | Widget type | Tag | Period | Other settings |
|---|---|---|---|---|
| 1 | Counter (output/rate) | Good_Parts | 8 hours | title "Good bottles (shift)" |
| 2 | Counter (output/rate) | Reject_Count | 8 hours | title "Rejects (shift)" |
| 3 | Bar chart (output per window) | Good_Parts | 8 hours | window = 1 hour, 8 bars |
| 4 | Number | Line_Speed | 8 hours | — |
How to read it: the big number is production for the period (counter resets are handled automatically), with the hourly rate underneath; the bars show which hours were strong or weak — gaps and short bars point at stops.
Recipe 2 — Downtime and faults
Answers: how much did the machine actually run, when did it stop, why?
Needs an on/off "running" signal recorded (e.g. Conveyor_Run); a numeric fault-code tag and a step-number tag make it much more useful.
| # | Widget type | Tag | Period | Other settings |
|---|---|---|---|---|
| 1 | State timeline | Conveyor_Run | 24 hours | — |
| 2 | Boolean (uptime/cycles) | Conveyor_Run | 24 hours | — |
| 3 | Error code (top-5 / events) | Fault_Code | 24 hours | — |
| 4 | Sequencer (time per step) | Step_Num | 1 hour | — |
How to read it: the ribbon shows when the machine ran (green) and stood (gray); the stats show uptime %, number of starts and cycle times; the error-code widget names the codes that cost the most time; the sequencer shows which step of the machine cycle eats the time.
Recipe 3 — Process monitoring (temperature, pressure, speed)
Answers: is the process value where it should be, and was it ever outside limits?
(Screenshot at the top of section 9.)
Needs an analog value recorded (e.g. Tank_Temp_C), with sensible limits.
| # | Widget type | Tag | Period | Other settings |
|---|---|---|---|---|
| 1 | Chart | Tank_Temp_C | 24 hours | H = 80, HH = 85, L = 60; Points 60 |
| 2 | Gauge | Line_Speed | 15 min | range 0–150, H = 130 |
| 3 | Counter (output/rate) | Good_Parts | 24 hours | — |
| 4 | Donut (uptime %) | Conveyor_Run | 24 hours | — |
How to read it: the shaded band is min–max per window — a short spike shows as a band spike even on a 24-hour chart (in the screenshot, the temperature spike crossed the orange H line during a jam); the dashed lines are your limits. Add an Out-of-spec % widget on the same tag to get "the value was outside limits X% of the time" as a number. Turn the same limits into an alarm in the next section.
11. Alarms and notifications
The Alarms tab watches recorded tags and tells people when something is wrong — on the screen, and optionally on a phone.
Rules
Rules run inside the recorder's poll loop, so a tag must be collected before it can be alarmed on (section 8). Press + New rule, or start from a template — Machine stopped, Drive fault, Value out of range — and fill in:
- Name and Tag.
- Severity — Info, Warning or Critical.
- Condition — value > H, value < L, outside L..H, value = H, value ≠ H, boolean ON / OFF, or fault code ≠ 0 for a fault-code tag; pick a Fault table and the alarm message names the fault, not just the number.
- Hysteresis — how far the value must come back before the alarm clears (stops chatter around the limit), and Min duration in seconds — how long the condition must hold before it counts.
- Message — what people should read; the tag's description under Settings → Recording is a good start.
Active alarms and history
Active Alarms lists what is firing now with severity and duration; the sidebar's Alarms badge shows the count from any tab. History keeps 90 days of alarm events — when each one started and cleared — for the shift handover and the post-mortem. Operators see rules, active alarms and history but cannot edit rules. An alarm is acknowledged at the device's own screen or from a computer on the plant network; over Tailscale (or any proxy) alarms can be seen but not acknowledged.
Notifications that leave the box
Settings → Notifications sends alarm events to a phone; the device otherwise needs no internet.
- Telegram — create a bot with @BotFather, paste its token, send the bot any message from your phone, press Detect chat ID. Free, works worldwide.
- WhatsApp (Meta Cloud API) — needs a free Meta developer app and a WhatsApp Business number: paste the access token, phone number ID and the number to send to. Free-text messages work within 24 hours of the recipient last writing to the number; outside that window a pre-approved template is required.
Fault code lookup
The Reference tab in the left menu carries built-in fault tables from the vendors' own manuals (drives, controllers). Type a code as the machine shows it — 59, F059, 0x22 — or a word like safety or watchdog, and read what it means before calling anyone. Operators have the tab too. The same tables feed the Error code dashboard widget and alarm messages.
12. Several machines on one device
Settings → Machines. Add a profile per machine ("Filling Line 1", …) — with the option to copy the current machine's collected-tag list, handy for identical lines. Each profile keeps its own controller address, recorded tags, favorites, panels, dashboards, alarm rules and history — completely separate. Give each machine a one-line description so everyone can tell the profiles apart; Archive the ones no longer in use (their history stays).
Switch the active machine from the dropdown in the top bar (visible once there are two or more profiles), or Activate it in Settings. Switching stops the recorder and disconnects from the current controller before changing over. Operators can see the active machine but not switch it.
13. Network and remote access
All under Settings:
- Wired network — the port that talks to the PLC. Shows cable state, current address and mode. Choose DHCP or Static and set the address right from the screen — e.g. if your PLC lives at
10.0.0.50, give the device10.0.0.20with prefix24. Gateway and DNS are optional; leave them empty on an isolated PLC network (internet keeps flowing over Wi-Fi). - Wi-Fi — see the current network, signal strength and address; Scan networks, tap one, enter its password, Connect.
- Setup hotspot — the device's own Wi-Fi network (LineKeeper-XXXX). By default it starts automatically when the device has no network; you can also start it by hand to use the panel from a phone where no plant Wi-Fi exists. The device has a single radio: starting the hotspot disconnects it from Wi-Fi (the wired port is not affected).
- Remote access — built-in VPN-based access (Tailscale) lets a trusted specialist (your OEM, integrator, or your own engineer at home) open the interface securely from anywhere — no router changes, nothing to type in a terminal. Enable shows a link and a QR code: approve the device from a phone or laptop with your plant's Tailscale account. Disable pauses remote access, Re-authorize moves the device to another account, Log out removes it from the network. The card also shows the Tailscale version, your network's name and when the device key expires — open the admin console from the card to disable expiry for an always-on device. Off by default, and nothing else on the device needs the internet.
- Device name — how the device appears in Tailscale, e.g.
linekeeper-line3, and in its addresslinekeeper-line3.<your network>.ts.net. Leave empty to use the system name. - Plant network access — the part a remote programmer needs. Tick the machine network the device is plugged into (the one marked PLC is on this network), add another network by address if needed, and press Open access. The device then works as a Tailscale subnet router: people you allow reach the PLC, the HMI and the drives as if they were on site. Each shared network is approved once in the Tailscale admin console — the card shows waiting for approval and links straight to the page. Close access stops the sharing instantly; remote users keep access to the device itself.
- Who can reach this device — every device in your Tailscale network that may connect to this one, with its owner and when it was last seen. Invite a specialist in the admin console (Users → Invite) and allow them in Access controls — per person, revocable at any time.
- Fix automatically — if the card warns that the device cannot control Tailscale, that network forwarding is off or that the Tailscale service is not running, one tap repairs it. The device also checks and repairs these on every start.
- Advanced options — use networks shared by other devices, Tailscale DNS (MagicDNS), SSH to the device over Tailscale, offering the device as an exit node, automatic updates of the Tailscale client. Each is a switch; the ones with consequences ask for confirmation.
Giving a programmer access to the machine network — the short version
- Settings → Network & remote → Remote access → Enable; approve the device with your plant's Tailscale account (link or QR code).
- Under Plant network access tick the machine network and press Open access; approve the route in the admin console when the card asks.
- Invite the programmer to your Tailscale network and allow them in Access controls.
- They install Tailscale on their computer (Linux users also turn on accept routes) and can open
http://<device name>:5000and the PLC's own address. When the job is done, revoke them in the admin console — or press Close access.
Over Tailscale the device is read-only. Whether a connection comes through Tailscale or through any proxy or tunnel in front of the device, it never writes to the PLC or to the panel's own outputs, for any role — the administrator included. Tag writes (also from Control Panel buttons and recipe tiles), output tests, output bindings and changes to the write unlock list, and alarm acknowledgment are refused with Writes are refused over a remote connection, and the attempt is recorded in the audit log. Do these at the device's own screen or from a computer on the plant network. Viewing data, settings, panels, alarm rules and updates still work remotely, and alarms can be seen but not acknowledged. A specialist who uses Plant network access reaches the PLC and the HMI directly, outside the device, so this rule does not cover that traffic.
Remote control is not internet access. Starting a function from a phone or a browser (section 19) works only from the plant network and only while a key switch at the device is in REMOTE. It changes nothing above: through Tailscale or any proxy the device still sends no command and accepts no change of the remote control settings, for any role. A remote connection can only read the state of remote control and press Release control.
Over Tailscale, remote access can be closed or narrowed, never opened or widened. Through a remote connection you can close Plant network access, remove a shared network from it, and switch the exit node and Tailscale SSH off. Opening the share, adding a network, or switching the exit node or Tailscale SSH on is refused with Remote access can only be opened or widened at the device or from the plant network; do it at the device's own screen or from a computer on the plant network. The other options (accept routes, MagicDNS, automatic updates, the device name) can be changed from anywhere.
Sharing this single machine with another company's Tailscale network (node sharing) gives access to the device only, not to the plant network behind it — for the network, invite the specialist as a member of your own network.
14. Users, passwords and the audit log
Settings → Users & passwords.
- Change passwords per role (administrator only; confirmed with the current administrator password). A password needs at least 8 characters and may not contain control characters (such as a line break or a tab), quotes (
"or') or backslashes, or start or end with a space. It also may not start with#, or contain a space followed by#, or${. The same applies to the first administrator password. Changing a password signs out all other devices using that role. Set the operator password on day one — the administrator password was created in the setup wizard. - Viewer password — read-only access for LineKeeper Go, monitoring tools and LineKeeper Up: a Viewer can read live values, alarms, charts and settings, and nothing else — no writes, no alarm acknowledgment, no changes. Off by default: press Set password (confirmed with the administrator password, at least 8 characters) to turn it on, Turn off to end it. Changing the password or turning it off signs out every Viewer session. A Viewer session lasts 365 days, so a phone or a monitoring tool does not have to sign in again. Viewer is for apps and tools (they sign in with the role viewer); the web sign-in screen offers only Operator and Administrator. LineKeeper Go can also start functions of the machine under a remote control key (section 19), but only with an Operator or Administrator sign-in. A Viewer never can.
- Operator screen without a password — on by default: the device's own display signs in as Operator at boot, like a hardware panel. Turn it off if the device's screen must not be usable without a password; browsers on the network always need one.
- People — who may sign in by name on the device's own screen (section 3). Add a person with a role and a 4–6 digit PIN (only a salted hash is stored; rename, change the PIN, switch the role or untick On to disable at any time). Add badge then hold the badge to the reader within a minute to register it; a badge can be removed again. The card shows who is at the screen right now, the idle sign-out times per role, the optional serial badge reader port, and the Shift log — every sign-in and sign-out by PIN, badge or access key. Access keys on the rear terminals point at people from this list.
- Active sessions — every signed-in device is listed with the way in (password, screen, PIN, badge, access key) and the person; Revoke signs one out instantly.
- Audit log — every login (including failed attempts and the screen's automatic sign-ins), every value written to a machine and every tag unlock/lock, with role, time, tag, value and result — and the person's name when someone was signed in by PIN, badge or key.
- Write access — the per-machine list of tags unlocked for writes (plus tags bound to Control Panel widgets). Lock any of them again with one tap.
Lost administrator password: ./reset_password.sh engineer on the device's service console prints a new one (see section 3).
15. Backup and export
Settings → Backup.
- Export config — downloads the active machine's configuration (recorded-tag list with modes and descriptions, operator panels, dashboards, recorder settings) as one
.jsonfile. Do it after finishing setup and keep the file somewhere safe; repeat for each machine profile. Alarm rules, users and network settings are not in the file. - Import config… — restores from such a file into the active machine (asks for confirmation — it replaces the machine's tags, panels and dashboards).
Recorded history is not part of the export; it stays on the device (and every dashboard widget can download its data as CSV, section 9).
16. Software updates and factory reset
Settings → Software Update shows the current version. The device installs signed releases published by LineKeeper — never arbitrary code — and checks for them by itself; when one is available, an Update available button also appears in the sidebar. Press Check for updates to look now, and Apply & Restart to install: the device downloads the release, swaps it in and restarts within a minute. If a new version fails to start, the device automatically rolls back to the previous working version and says so in the update card. Recorded data, panels and settings are not touched by updates.
Factory reset (Settings → Factory Reset) erases everything on the device — machines, tags, operator panels, dashboards, alarm rules, collected history, notification settings and sign-ins. Network settings, passwords and the installed software are kept. The device restarts into the first-boot screen. Export the configuration first if you might want it back.
17. Using the built-in screen (full-screen mode)
Out of the box the device boots straight into the Control Panel, full screen, signed in as Operator, with no desktop and no login prompt for the screen itself.
- An on-screen keyboard pops up automatically when you tap a text field (⌨ button in the bottom-right corner opens/closes it manually).
- To do setup work on the device's own screen, press Logout: the sign-in form stays on screen, so choose Administrator and enter the password; the full menu appears. To hand the screen back, log out and press Open the operator screen — no password (or simply reboot).
- To leave full-screen mode for maintenance (administrator only): Settings → Kiosk → Close window, or tap the bottom-left corner of the screen three times quickly and enter the PIN (default 1234).
- The built-in screen is compact — best for the Control Panel and day-to-day viewing. For building dashboards or long configuration sessions, open the same interface from a browser on your computer.
18. Rear terminals — serial ports, inputs and outputs, access keys, USB sticks
The 7″ and 10″ panel models carry a row of screw terminals on the back. Everything below is in Settings → Hardware (the Hardware card shows what the device detected; on the box model or a laptop it simply says so).
Serial ports (RS-485 / RS-232)
| Port | 10″ panel terminals | 7″ panel terminals | Used for |
|---|---|---|---|
| RS-232 #1 | 9–10 | 3–4 | The service console by default (a technician can log in with a serial cable). Press Free RS-232 #1 for equipment in the Hardware card and restart to use it for a device; Restore the service console brings it back. |
| RS-232 #2 | 7–8 | 5–6 | Free |
| RS-485 #1 (A/B) | 5–6 | 9–10 (or RS-232 #3 on 7–8) | Modbus RTU |
| RS-485 #2 (A/B) | 3–4 | 13–14 (or RS-232 #5 on 11–12) | Modbus RTU |
| CAN | 1–2 | 15–16 | Present, not used by the software |
- To connect over a serial port: PLC tab → protocol Modbus TCP/RTU → Link: Serial (RTU) → pick the port from the list (the panel's terminals first, then any USB serial adapter), set baud, parity, stop and data bits as printed in the equipment's manual, fill in the tag map, Connect. The choice is saved with the equipment profile.
- RS-485 is a two-wire half-duplex bus: mind A/B polarity. The panel has no 120 Ω termination — add a resistor across A/B at the far end on long or noisy runs.
- On the 7″ panel each RS-485 port shares its circuit with an RS-232 pair of terminals; the factory wires one of them. Pick the name printed on the rear label in the Hardware card — this only changes how the port is listed.
Inputs and outputs
Four isolated inputs (IN1–4) and four isolated outputs (OUT1–4) sit on their own terminal block. Supply 5–24 V DC to VDD_ISO / GND_ISO (10″: terminals 12 / 11, 7″: 10 / 9); inputs read 5–24 V against GND_ISO, outputs switch that supply at up to 500 mA each.
| 10″ terminals | 7″ terminals | |
|---|---|---|
| IN1 · IN2 · IN3 · IN4 | 6 · 5 · 4 · 3 | 4 · 3 · 2 · 1 |
| OUT1 · OUT2 · OUT3 · OUT4 | 10 · 9 · 8 · 7 | 8 · 7 · 6 · 5 |
- Inputs are tags —
LK.IN1…LK.IN4appear next to the controller's own tags: put them on the operator panel, record them, write alarm rules on them (an andon push button, a "machine running" contact, a door switch). In the inputs table give each one a label and tick Inverted for a normally-closed contact (the input reads ON with nothing connected); an input registered as an access key is marked as such. An input can also be the remote control key (section 19). It is marked as such, and it can be neither Inverted nor an access key. - Outputs drive a stack light or a siren. In the Hardware card each output gets a source: any active alarm, alarms of a given severity or worse, PLC disconnected, recording stopped, line stopped (the running tag chosen in Diagnose), a tag condition, or Manual. Tick Blink for a flashing lamp, Invert to swap on and off. Alarm-driven outputs need Recording on. Two more sources, Remote control lamp and Remote control warning, are assigned only in the Remote control card (section 19): the lamp is on while remote control is enabled and blinks during the warning before motion, and the warning output is on during that warning.
- Manual outputs are panel buttons — bind a toggle to
LK.OUT1…LK.OUT4and the operator switches the lamp from the screen; every press is in the audit log. Test on / off in the Hardware card lets an administrator check the wiring (a bound output follows its source again after ten seconds). While a remote control key is assigned, outputs are tested at the device screen. - Outputs are de-energized whenever LineKeeper is not running (restart, power loss). Wire a lamp normally-closed or tick Invert if it must be on in that case. Manual outputs come up Off after a restart.
Access keys
A key switch wired to an input identifies a person. In Settings → Hardware → Access keys give each key a name, pick the person it belongs to from the People list (Settings → Users & security) and a role. Turning an administrator key signs the device's own screen in without a password; turning an operator key signs the operator in by name — every write in the audit log then carries that name, and the Shift log keeps the key-in / key-out times next to the PIN and badge sign-ins. Removing the key ends the session at once. A key and a badge or PIN at the same time: the higher role is in charge of the screen. Keys act on the device's own screen only; phones and laptops keep the password login. The input of the remote control key (section 19) cannot also be an access key.
Badge readers
A USB RFID reader (125 kHz or 13.56 MHz badges) that types the badge number like a keyboard works on the device's screen with no setup: plug it into a USB port, register badges in the People card (Add badge, then hold the badge to the reader within a minute) and people sign in by holding their badge. A reader that talks over a USB serial port is chosen in the People card (Serial badge reader, e.g. /dev/ttyACM0) and behaves the same. An unregistered badge shows Badge not registered and is written to the audit log.
USB sticks
A FAT32 or exFAT stick in a USB port shows up in Settings → System → Backup within a few seconds.
- Export to USB stick writes a folder
LineKeeper-<device>-<date>with the equipment's config, the recorded events of the last days as CSV, the learned model, the stored PLC program and HMI export, the device log and a README. Wait for Safe to remove. - Import from USB stick… lists config exports,
.L5Xprograms, HMI exports and.lkmodelfiles on the stick; Preview shows what is inside, then apply. - Update from USB stick: copy a release bundle (
manifest.json,manifest.sigand thelinekeeper-v….tar.gzfrom the release page) onto the stick; the Software Update card offers it when it is newer than the installed version. Only bundles signed by LineKeeper install; an older release is reported, never applied. The device restarts into the new version like an online update.
The TF-card slot on the panel models is for the operating system only; it is not a storage slot.
19. Remote control and safety
What it is. Remote control lets one person start a function of the machine from a phone (LineKeeper Go) or from a browser on the plant network, while standing where they can see the machine. It exists for one situation: the device's panel is far from the station you are working at. You turn a key switch at the panel to REMOTE, walk to the station, and start a function from your phone while you watch it run.
The key switch is the permission. Once a key is assigned, this device accepts no command from a phone or a browser unless someone at the device has turned the key to REMOTE, and the permission runs out by itself. A phone that reaches the PLC by another route is outside this: see What the key does not protect against. Remote control is off until an administrator sets it up. With no key assigned, LineKeeper Go can only watch this device and the web panel in a browser works as it always did.
What it is not. Read these four statements before you set it up. The Remote control card and the remote control sheet in LineKeeper Go show them too.
How it works, in short
- The key switch has two positions: LOCAL (no permission) and REMOTE.
- Turning the key from LOCAL to REMOTE opens a time-limited permission. This section calls it the window. It lasts 15 minutes by default and is never extended.
- Inside the window one person at a time takes control and starts functions from a list the administrator prepared. Everyone else can watch.
- Before a function that moves the machine starts, the device warns the people at the machine: a beacon, a horn and a countdown on the device screen.
- The window ends when the key goes back to LOCAL, when the time is up, when someone presses Cancel remote control on the device screen, or when the settings or the PLC connection change. To go on, turn the key to LOCAL and back to REMOTE.
- Over Tailscale or any proxy the device accepts no command, whatever the key says.
Setting it up — three steps
An administrator does this in Settings → Hardware → Remote control, at the device's own screen or from a computer on the plant network. Over Tailscale the card can be read but not changed. Until a key is assigned the card says Remote control is off. Assign a key switch to turn it on. It shows the same three steps as below, and the four statements above stay visible in it.
Once the device screen is paired, the key is changed only at that screen. Pairing (The device screen must be paired) is the device learning which touchscreen is its own. From then on three things are done at the paired device screen and nowhere else: assigning, changing or removing the key; unpairing the screen; and a factory reset. From a laptop the device answers The remote control key is changed at the device screen. Everything else in the card (the time limit, the warning, the list of functions, the beacon and horn outputs, the safety review) can still be saved from a computer on the plant network. A device whose screen is not paired (an LK Box, or a panel that is still being set up) lets the plant network set the key, as before. So the order on a new panel is: wire, assign the key, pair the screen. If the inputs are set to active-low, the order is the other way round: pair first, then assign. With the inputs set to active-low the device refuses to assign a key from anywhere but the paired screen: The inputs of this device are set to active-low. Pair the device screen and assign the key there, then do the key test.
Step 1 — wire the key switch. Wire a key switch to one of IN1–IN4: +24 V through the switch contact to the input, so that +24 V on the input means REMOTE. A broken wire then reads LOCAL. The terminals and a wiring table are in Wiring the key switch below.
Step 2 — choose the input as the key, then test it. Choose that input here as the key. An input that cannot be the key is greyed out, with the reason. Two kinds cannot: an input marked Inverted, and an input registered as an access key (section 18). While a key is assigned, the inputs table does not let you mark the key input Inverted either (for IN2 it says IN2 is the remote control key. Change it in Settings → Hardware → Remote control.). The key input is marked Remote control key in the inputs table.
While a key is assigned, the inputs and outputs are set up at the device screen. The inputs and outputs table in Settings → Hardware (labels, Inverted, what drives an output) can be saved only at the paired device screen, and the output test is done there too. From a laptop the device answers While a remote control key is assigned, inputs and outputs are set up at the device screen. (An output that is left on by a setting could otherwise be switched on from the plant network.) Set the inputs and outputs up first if you can, and assign the key afterwards.
Then the key test. The card shows the live reading of the key. Turn the key to LOCAL — this shows LOCAL. Turn it to REMOTE — this shows REMOTE. Remove the wire — this must show LOCAL. Do not skip the last part. It proves that a broken wire can never give permission. If the card still shows REMOTE with the wire removed, do not use remote control: find out why the input still has voltage (another wire, a bridged terminal) and repeat the test.
Step 3 — choose which functions may be controlled remotely. Choose which functions may be controlled remotely. The list is empty until you add to it, and it belongs to the machine profile (section 12): each machine has its own list, up to 32 functions. A function is one PLC tag with a mode:
| Mode | What the device does | Typical use |
|---|---|---|
| Pulse | Writes 1, waits the pulse time (500 ms unless you set another, 100–2000 ms), writes 0. The phone cannot change the time. | Start cycle, reset |
| Hold | Writes 1 while the finger is on the button, 0 when it lifts. At most 60 seconds at a time. | Jog |
| Setpoint | Writes a value once and leaves it. A number (you set the minimum, maximum and unit) or an on/off value. | Speed, a recipe number, a mode switch |
An on/off setpoint is for modes, not for anything that moves. An on/off value is written once and stays on, even if the phone loses its connection a second later. So the device does not save an on/off setpoint for a function that can move the machine or switch on an actuator. It answers Use hold or pulse for a function that moves the machine. An on/off value would stay on after a lost connection. The function editor says the same, under the box This function can move the machine or switch on an actuator, and does not send it. For something that moves, use Pulse or Hold. Use an on/off setpoint for a mode or a recipe flag, and clear the box for it. (A number setpoint that moves the machine, such as a speed, is allowed. It needs the safety review and gets the warning.)
For every function the administrator also:
- gives it a label (what people read on the phone; the tag name if left empty);
- leaves This function can move the machine or switch on an actuator ticked, or clears it. It is ticked for every new function. Only functions with it ticked get the warning before motion, and only these need the safety review below;
- ticks the confirmation: I confirm this function is safe if its bit stays on (or its value stays set) after a lost connection: the PLC program stops it by itself (a timeout or the heartbeat), or that state cannot hurt anyone. The PLC program pattern below says what this means;
- may name a heartbeat tag for a pulse or hold function (see the same section). It must be a DINT (or another wide integer) that the device reads now, so the PLC must be connected when you save it: The heartbeat tag must be an integer tag the device reads now.
Tags in a safety program, the key tag and the panel's own inputs and outputs (LK.IN1…LK.OUT4) can never be on the list. Tag names are compared without regard to case, as in the PLC: RC_Jog and rc_jog are the same tag, so the same tag cannot be listed twice or be both a function and a heartbeat, and a command for rc_key is a command for the key tag.
The machine-safety review. A machine-safety specialist must review this setup before any function that moves the machine is enabled. The card has a field Machine-safety review: reviewed by … on …. Enter who reviewed the setup and the date. Until it is filled in, the device refuses to save a function that moves the machine. The device cannot judge the review. It only requires that someone has recorded it.
The other settings in the card:
- Time limit (minutes, 1–60) — how long a window lasts. Default 15.
- Warning before motion (seconds, 1–10) — default 3. It is never zero.
- Beacon output and Warning horn output — see Recommended: key, lamp and horn.
- Pair this screen — see The device screen must be paired.
Every change saved in the card ends any open window, so the list can never change under a running command. It can be widened only on site (at the screen or on the plant network), never over a remote connection.
While a key is assigned, the function list replaces the write unlock list for everything that is not the device's own screen. The unlock list (Settings → Write access) keeps governing the device's own screen. Adding a function does not unlock the tag for the screen, and unlocking a tag does not add it to the list.
Wiring the key switch
The key switch gives the device a yes or no: voltage on an input means REMOTE, no voltage means LOCAL. Use the isolated inputs of the rear terminal block (section 18). In short: +24 V through the key switch contact to the input.
| Wire | From | To | 10″ panel | 7″ panel |
|---|---|---|---|---|
| 1 | +24 V DC of your supply | VDD_ISO | terminal 12 | terminal 10 |
| 2 | 0 V of the same supply | GND_ISO | terminal 11 | terminal 9 |
| 3 | +24 V of the same supply | one side of the key switch contact | — | — |
| 4 | the other side of the contact | the input you chose as the key | IN1 · IN2 · IN3 · IN4 = 6 · 5 · 4 · 3 | IN1 · IN2 · IN3 · IN4 = 4 · 3 · 2 · 1 |
With the key in REMOTE the contact is closed and the input sees +24 V. With the key in LOCAL the contact is open and the input sees nothing. The point of wiring it this way is that every fault reads LOCAL: a broken wire, a blown fuse or a lost 24 V is the same as LOCAL. A key wired the other way round would give permission when something broke. That is why the key input cannot be marked Inverted.
To the device, a key turn is voltage going away and coming back. Work on the key circuit that does the same thing, such as replacing a fuse or reconnecting a terminal while the key is in REMOTE, looks like a turn too. Turn the key to LOCAL, and take it out, before you work on the key circuit or its 24 V supply.
Recommended: key, lamp and horn
The Remote control card says: Recommended: a key switch with two contacts — the second one to a PLC input that the PLC program uses as a permissive — and a key that can be removed only in LOCAL, so the person working at the machine takes it along.
- A key switch with two contacts. The first goes to the device as above. The second goes to a PLC input that the PLC program uses as a permissive (the PLC program pattern). Then even a phone that writes straight to the PLC is stopped by the key, and the PLC refuses a command even if the device gets it wrong.
- A key that can be removed only in LOCAL. Whoever works at the machine takes the key along, so nobody can turn it to REMOTE while they are inside the machine.
- A beacon (stack light) output. In the card, Beacon output picks one of the panel outputs. It is on while a window is open and blinks during the warning before motion. If none is assigned, the card says No beacon output is assigned. People at the machine see remote control only on this screen. Wiring a lamp from the key switch's own contact also works and does not depend on the device.
- A warning horn output. Warning horn output picks another panel output. It is on during the warning before motion, together with the blinking beacon.
Only an output that is not used for anything else can be picked. The card marks them Remote control lamp and Remote control warning in the outputs table. They are set only in the card: the general outputs editor cannot assign or change them, and the output test is refused on them. Wire only lamps and horns to the panel outputs (section 18). The outputs are off whenever the device software is not running, and remote control is off then too.
The key left in REMOTE is a question for your plant's procedure. The device cannot know who holds the key or whether anyone is still at the machine. Decide who may turn the key, where it is kept, and that it goes back to LOCAL and is removed when the work is done. The device does make sure of this much: a key left in REMOTE does not keep the permission alive. The window ends when its time is up, and nothing opens again until the key is turned to LOCAL and back to REMOTE.
A device without inputs (LK Box)
The box model has no input terminals. The card says: This device has no inputs. Use a PLC tag as the key: wire the key switch to a PLC input and choose that input's tag here (1 = REMOTE). If the PLC connection is lost, the key reads LOCAL. A panel model can use a PLC tag as its key too.
- The tag must be an on/off (BOOL) tag that the device reads now. It cannot be a safety tag or one of the panel's own inputs or outputs. The device never writes to it.
- A tag key is only as physical as the PLC program makes it. The device cannot tell a physical input from an internal bit. If the key tag is a bit that another panel or a program can set, then it is not a key. Choose the PLC input point itself, such as
Local:1:I.Data.5on a Logix PLC, a Modbus discrete input, or an S7Ibit, and make sure nothing in the program copies a software bit onto it. - If the PLC connection is lost, the key reads LOCAL and the window ends. When the connection comes back with the key in REMOTE, nothing opens: that is not a person turning a key. Turn the key to LOCAL and back to REMOTE.
- The key tag belongs to one machine profile. With another machine active, the key reads LOCAL.
- Run the same key test as above. Removing the wire must show LOCAL.
How a session goes
- Turn the key. The device must see the key at LOCAL first, and then see it stay at REMOTE for about a third of a second. Then the window opens for the time limit, 15 minutes by default. The beacon comes on, if one is assigned. The device screen shows a banner. If a notification channel is set up, a message goes out. The audit log records it.
- Take control. In LineKeeper Go, open the remote control bar of this device and press Take control. The first time, the app asks for Your name, shown on the machine's screen. In a browser on the plant network, press Take control in the banner (the name is the signed-in person's name, or else the role: Operator or Administrator). The name, and whether it is a phone or a browser, appear on the device screen. Only an Operator or an Administrator can take control. A Viewer never can. In LineKeeper Go, taking control and sending commands needs Pro, like any other write from the phone.
- One person controls at a time. The others see
<name> is controlling this machine.and can watch. Nobody can take control away. Control ends when the holder presses Release control, signs out or is signed out, or when the window ends. The device's own screen cannot take control: The device screen writes directly; remote control is taken from a phone or a computer on the plant network. - Start functions. See the next part. Controls are active only while you hold control, only for functions on the list, and only when the control matches the function's mode.
- Release control. Press the big Release control button when you are done. The window stays open until its time is up, so you or someone else can take control again without turning the key.
- The window ends. By the key, the time limit, Cancel remote control, a change of settings or PLC connection, a restart of the device, or a key that cannot be read. The device writes 0 to everything it switched on (the table in What happens when something fails shows when that cannot be guaranteed). Setpoints keep the values they were given. The window is never extended. For another one, turn the key to LOCAL and back to REMOTE.
While this phone holds control the app always shows Not an emergency stop., the countdown (Ends in 12:40) and Release control, and keeps the phone's screen awake.
A key turn is the only way in. A key left in REMOTE across a restart of the device, a timeout, a cancel, a settings change or a PLC change opens nothing. The device says so: for example Remote control timed out. Turn the key to LOCAL and back to REMOTE.
The warning before motion
Before the first motion command in a window, and again after 60 seconds without one, the device waits before it writes anything. The wait is the Warning before motion time, 3 seconds by default:
- the beacon blinks and the horn output is on (if they are assigned);
- the device screen shows a red countdown;
- LineKeeper Go shows a countdown. For a hold it says Keep holding — warning the people at the machine. A browser shows
Starting <label> in 3 s — people at the machine are being warned.
If the window ends, control changes hands or the key goes to LOCAL during the warning, nothing is written. A function that the administrator marked as not moving the machine does not warn.
Pulse, hold and setpoint from the phone
- Pulse. One press sends one command. The device itself writes 1, waits the pulse time and writes 0, so the phone never sends two writes. If the phone loses its connection after the press, the pulse still finishes. Release control, the key, Cancel remote control and the timer end it early, and the device writes the 0 at once. With the longest warning a pulse command takes up to 12 seconds from the press.
- Hold to run. The device writes 1 while your finger is down and 0 when it lifts. While you hold, the phone tells the device every 0.2 seconds that you are still there. If nothing arrives for 0.75 seconds the device writes 0. The app shows Link lost — released. A single hold lasts at most 60 seconds. When the app goes to the background, every hold is released. You keep control and can use it again when you return, until the window ends.
- Setpoint. A number is checked against the minimum and maximum of the function:
Enter a value from <min> to <max>.The value is written once. It stays after the window ends. A setpoint is not set back by the device. - One command at a time. A second command while one is running gets Another command is still running.
Which control goes with which function:
| On the phone or the web panel | Needs a function in this mode |
|---|---|
| Hold-to-run (momentary) button | Hold, or Pulse (a press sends one pulse) |
| Pulse button | Pulse |
| On/off button (toggle, latch) | Setpoint, on/off (only for a function that does not move the machine) |
| Number field | Setpoint, number |
A control for another mode stays greyed out: On this device <label> is a <mode> function. A tag that is not on the list gets This tag is not on the device's remote control list.
On the device screen
The banner sits above every view, also on the full-screen panel and on the sign-in page. It cannot be dismissed. It shows:
- Window open, nobody in control:
REMOTE CONTROL ENABLED — nobody has taken control yet · ends in 14:12and the button Cancel remote control. - Someone in control:
REMOTE CONTROL ACTIVE — <name> (<phone | browser>) can start functions of this machine · ends in 12:40and the same button. - Warning (full width, red):
MOTION IN 3 s — <name> is starting <label> - A command that may still be on:
Remote control: <label> may still be ON in the PLC — the device could not switch it off. Check the machine. - A screen that is not paired: see The device screen must be paired.
- After Cancel remote control: Remote control cancelled. Turn the key to LOCAL and back to REMOTE to allow it again.
Cancel remote control is one tap, with no question and no password. It ends the window for everyone. It is not an emergency stop either. The device's own screen keeps working during a window as it does at any other time.
The web panel in a browser
A browser that is not the device's own screen, such as a laptop on the plant network, follows the same rules once a key is assigned. Every write from it needs the key in REMOTE, control taken, and a function on the list. The panel shows a banner:
- Key at LOCAL:
Turn the key to REMOTE to control from this browser. - Window ended: the device's message, which ends Turn the key to LOCAL and back to REMOTE.
- Window open:
Remote control is enabled for 14:12. [Take control] - You control:
You are controlling this machine — ends in 12:40. Not an emergency stop. [Release control] - Someone else controls:
<name> is controlling this machine. You can watch. - Warning:
Starting <label> in 3 s — people at the machine are being warned.
Momentary buttons on the Control Panel run as hold-to-run or pulse. On/off buttons and number fields write setpoints. Recipe tiles and the other writes from a browser are setpoint writes: they need a Setpoint function on the list. A tag that is not on the list is refused: <tag> is not on the remote control list of this device. A momentary button is released when the page is hidden or closed.
Panel outputs and the output test only at the device screen. The panel's own outputs (LK.OUT1…LK.OUT4) are indicators, not remote functions. From a browser, Panel outputs are not controlled remotely. and While a remote control key is assigned, outputs are tested at the device screen. An output that shows remote control cannot be switched by hand at all.
With no key assigned, LineKeeper Go cannot control this device. The web panel works as before: the write unlock list decides what a browser on the plant network can write. The device cannot tell a phone's browser from a laptop's, so a phone that opens the web panel on the plant network writes the same way.
The device screen must be paired
What pairing is. The device has to tell its own touchscreen from anyone who reaches the device by a port forward or a tunnel on the device itself. So the screen is paired: the device gives its browser a secret code, keeps only a fingerprint of it, and checks the code every time the screen writes while a key is assigned. One screen is paired at a time. Pairing again replaces the old code.
When the card asks for it. If an administrator assigns the key at the device's own screen, the card asks for the administrator password and pairs the screen. The card then says This screen is paired. If the key is assigned from a laptop, the card there says Pair the device screen — do this on the device itself. The card and the device screen show Pair this screen until someone does it at the device.
Who can pair. Only an administrator, at the device itself, and always with the administrator password. The card asks for it every time, also when the administrator signed in at the screen with an access key or a badge: those sign-ins do not pair a screen. Pairing cannot be done from a laptop or a phone.
What the banner means. This screen is not paired. While a remote control key is assigned, writes from this screen are blocked. An administrator pairs it in Settings → Hardware → Remote control. The screen can still be read and signed in to, but while a key is assigned its writes stop. Fix: at the device screen, sign in as administrator, open Settings → Hardware → Remote control, press Pair this screen.
Unpairing. Unpair this screen in the same card, at the paired screen, removes the pairing. While a key is assigned the screen then does not write until it is paired again. Once a screen is paired, a laptop cannot unpair it: the button there is greyed out, and the device answers The remote control key is changed at the device screen. If the screen was lost or its storage was wiped, pair it again at the device (with the administrator password): pairing again replaces the old pairing, and the new screen can then unpair or change the key as before.
Good to know:
- Until a key is assigned, nothing changes for the screen after an update.
- Pairing and a factory reset (which clears the pairing) both end any open window. Once a screen is paired, a factory reset is done at that screen too.
- If the screen forgets its stored data, for example after the screen software was reset or if it runs in a private mode, pair it again.
- Pairing is recorded in the audit log and sent to Telegram:
The device screen of <equipment> was paired.Someone who forwards a port to the device and knows the administrator password can pair their own browser. The real screen then loses its pairing, shows the banner, and the pairing is in the audit log and in Telegram.
Over the internet nothing changes
Remote control is not internet access. It works only from the plant network and only while the key is in REMOTE. Through Tailscale or any proxy or tunnel (section 13) the device stays read-only for everybody, administrator included: taking control, pulse, hold, setpoint, pairing and every change of the remote control settings are refused. LineKeeper Go says: Commands are never sent over a remote connection (Tailscale or a proxy). Use the plant network. What still works from anywhere is reading the state and pressing Release control.
A specialist who uses Plant network access reaches the PLC directly, outside the device. The key does not see that traffic (the third statement at the top).
What happens when something fails
The device switches a command off by writing 0. This table says, in plain words, what each failure does. The last column is the one that matters: in the rows marked No, only the PLC program can stop the machine.
| What happens | What the device does | Does the command end without the PLC program? |
|---|---|---|
| The phone loses Wi-Fi | Hears no beat from the phone for 0.75 s and writes 0. | Yes. Off after about 0.8 s plus the time to write. |
| The app goes to the background | The app lets go and closes its connection. A frozen app is caught by the same 0.75 s rule. | Yes |
| The app or the phone crashes | The connection closes, or the 0.75 s rule ends the hold. | Yes |
| The key is turned to LOCAL | Within about 0.2 s writes 0 and ends the window. | Yes, while the device runs and can reach the PLC. |
| The time limit ends | Writes 0 and ends the window. | Yes |
| Cancel remote control at the screen | Writes 0 and ends the window. | Yes |
| A planned restart of the device software (update, Restart, reboot) | Writes 0 first. | Yes, if the PLC answers within 3 s. |
| The device software crashes, is killed, or the watchdog (90 s) restarts it | Nothing until it starts again. After it reconnects to the same PLC it writes the 0. | No. The command stays on for the restart, the start and the connection: at least about 10 s and up to 2 minutes. |
| The device loses power | Nothing. After it boots and connects it writes the 0. | No. Stays on until the device is back, and for ever if it never comes back. |
| The cable to the PLC is pulled | The 0 cannot be written. The device remembers the command, raises an alarm and ends the window. When the link is back it writes the 0. | No. Stays on until the cable is back. |
| The PLC refuses the 0 | Tries three times, 0.1 s apart, then acts as in the row above. | No. May stay on. |
| The device software is busy and its checks run late | The checks run late, so the 0 comes late. | Partly |
A pulse is handled the same way as a hold. Only the PLC can close the No rows (the PLC program pattern).
When the device cannot confirm a 0. It does not forget the command. It keeps a record of every command it switched on, on its own storage, before it writes the 1. While a 0 is not confirmed:
- the device raises the critical alarm Remote control: release not confirmed, with the message
<label> may still be ON in the PLC.It shows in the alarm lists, also in LineKeeper Go; - remote control is blocked: no window opens and no command is accepted. The device screen shows
Remote control: <label> may still be ON in the PLC — the device could not switch it off. Check the machine.LineKeeper Go showsThe device could not confirm that <label> was switched off. Remote control is blocked until it is. Check the machine.; - Telegram sends
ALARM — <equipment>: after remote control the device could not switch off <label> (<tag>). It may still be ON in the PLC. Check the machine.; - the device tries again, every 2 seconds, whenever it is connected to the same PLC. If the cable was pulled, that starts when the link is back. If the device was restarted, it starts at the first connection to the same PLC. A record that belongs to another PLC waits until that PLC is connected. When the PLC takes the 0, the message goes away and the alarm closes;
- the record names the PLC by its address (protocol, address and slot) and the tag by its name. A PLC replaced at the same address gets the late 0 on that tag name: if the new PLC has a tag of that name that means something else, it receives a 0 it was never meant to receive. That is the safe direction (a 0 switches a bit off), but check the tag names of a replacement PLC before the device reconnects to it, or clear the message first;
- until then, check the machine. After checking it, an administrator can clear the message in Settings → Hardware → Remote control with I checked the machine — clear this, at the device screen or from a computer on the plant network. Clearing writes nothing to the PLC. It only tells the device that a person has checked. It is recorded in the audit log.
The PLC program pattern
The device alone cannot close the No rows above. The PLC program can, and this is what the confirmation for each function asks you for. The pattern:
- A request bit, not the output. LineKeeper writes a request bit (
LK_Jog_Req). It never writes the output itself. The PLC program decides whether the machine moves. - A heartbeat. Give the function a heartbeat tag (
LK_HB, a DINT). While the request is 1, the device adds to it every 250 ms. The PLC program stops acting on the request when the number stops changing. - The key's second contact as a permissive. Wire the second contact of the key switch to a PLC input (
Remote_Key_Input) and use it as a permissive. A phone that writes straight to the PLC is then stopped by the key too, and the PLC refuses a command even if the device is wrong. - A one-shot or a timeout for pulse functions. Give every pulse function its own one-shot or timeout in the PLC program.
An example in ladder logic (Logix), three rungs. It is a pattern, not a finished program: adapt the names and the timer to your PLC, add the machine's own permissives, and have it reviewed with the rest of the setup.
| Rung | Instructions | What it does |
|---|---|---|
| 1 | NEQ(LK_HB, HB_Last) then MOV(LK_HB, HB_Last) and OTE(HB_Changed) | In every scan in which the heartbeat differs from the remembered number: remember it and switch HB_Changed on for that scan. |
| 2 | XIO(HB_Changed) then TON(HB_Tmr, 1000 ms) | A timer of 1 s that starts again each time the heartbeat changes. It finishes when the heartbeat has not changed for 1 s. |
| 3 | XIC(LK_Jog_Req) XIC(Remote_Key_Input) XIO(HB_Tmr.DN) and the machine's permissives, then OTE(Jog_Allowed) | The machine may jog only while the request is on, the key's second contact says REMOTE, the heartbeat is alive and the machine's own permissives are true. |
In Structured Text the timer of rung 2 is HB_Tmr.PRE := 1000; HB_Tmr.TimerEnable := 1; HB_Tmr.Reset := HB_Changed; TONR(HB_Tmr);.
What the key does not protect against
- A phone that writes to the PLC directly (LineKeeper Go connected straight to the PLC). The key on this device does not see it.
- A PLC tag used as the key, when the PLC program lets something else set that tag.
- Anyone who can sign in to the device's operating system, over SSH for example. They control the device and the PLC network behind it, key or no key. Only a key wired into the PLC program stops that.
- A browser on the plant network when no key is assigned (see above).
- A power loss, a crash or a pulled cable while a command is on (the No rows).
What the audit log and Telegram show
The audit log (section 14) carries these entries. Each has the role, the person if signed in by name, the client, and where the request came from.
| Entry | When |
|---|---|
remote_on | The key was turned to REMOTE and a window opened. |
remote_off | A window ended. The reason and the tags that were switched off are in the entry. |
remote_take | Someone took control (with the name they gave). |
remote_release | Control ended: released, or the holder's session ended. |
remote_cancel | Cancel remote control was pressed at the screen. |
remote_pulse, remote_set | Each pulse and each setpoint, with the result. |
remote_hold_on, remote_hold_off | Each hold, with the reason it ended and whether the 0 was confirmed. |
remote_refused | A command was refused, with the reason. The same refusal from the same session for the same tag is recorded once in 10 seconds. |
remote_release_failed, remote_release_cleared, remote_release_dismissed | A 0 was not confirmed, was confirmed later, or was dismissed by an administrator. |
remote_config, remote_functions | The settings or the function list were saved. |
screen_paired, screen_unpaired | The device screen was paired or unpaired. |
write_tag | A write from a browser on the plant network. With a key assigned the entry says remote. |
vpn_refused | A command over a remote connection was refused. |
If a notification channel is set up (Settings → Notifications, section 11), the device sends these messages, whether or not alarm forwarding is switched on. Times are the device's local time.
- Window opened:
Remote control ON — <equipment>: the key switch was turned to REMOTE. It ends at <HH:MM> or when the key goes back to LOCAL. - Control taken:
Remote control — <equipment>: <name> (<phone | browser>) took control. - Window ended, with the reason:
Remote control OFF — <equipment>: <reason>.The reasons are: the key switch was turned to LOCAL, the key switch could not be read, the time limit ran out, it was cancelled at the device screen, the remote control settings were changed, the PLC connection was changed, a command could not be switched off, the device is restarting. - A 0 not confirmed:
ALARM — <equipment>: after remote control the device could not switch off <label> (<tag>). It may still be ON in the PLC. Check the machine. - Screen paired:
The device screen of <equipment> was paired. - Settings changed:
Remote control settings of <equipment> were changed by <person or role> (<origin>).It is sent for every saved change of the card's settings or of the function list, so a change made from the plant network is seen.<origin>isscreenorlan.
<equipment> is the name of the active machine profile.
Troubleshooting remote control
| Symptom | What it means | What to do |
|---|---|---|
| The card shows LOCAL, but the key is in REMOTE | The input sees no voltage. A broken wire, a blown fuse and a lost 24 V all read LOCAL. | With the key in REMOTE, measure +24 V at the input terminal and between VDD_ISO and GND_ISO. Check the terminal numbers (wiring table). Repeat the key test. For a PLC tag key: is the PLC connected, is the tag an on/off tag, is it 1 when the key is in REMOTE, is the right machine active? |
| The card says the key cannot be read | Panel input IN2 cannot be read. or No PLC connection — the key tag cannot be read. The device treats this as LOCAL. | Fix the wiring or the PLC connection. When it reads again, turn the key to LOCAL and back to REMOTE. |
| The key is in REMOTE and nothing opens | The device did not see LOCAL first, or REMOTE did not stay long enough. After a restart, a timeout, a cancel, a settings change, a PLC change or an unreadable key, a window needs a new turn. | Turn the key to LOCAL and back to REMOTE. |
| The card says the settings cannot be read | The remote control settings on this device cannot be read. An administrator sets them again in Settings → Hardware → Remote control. The stored settings are damaged. The device treats this as a key that is assigned but unreadable: the state is LOCAL and nothing can be controlled remotely. | An administrator saves the settings again (choose the key, or Turn remote control off), at the paired screen if there is one. |
| The window ends too early | Someone turned the key, pressed Cancel remote control, saved settings, or the PLC connection changed (Connect, Disconnect, another machine). | Open the audit log: remote_off gives the reason. |
| A hold stops by itself | The Wi-Fi was weak, the app went to the background, or 60 seconds passed. | Keep the app in front, move closer, and hold again. |
| The screen shows This screen is not paired. | A key is assigned and this screen has no pairing. Its writes are blocked. | The device screen must be paired. |
| The device screen shows that a command may still be ON | The device could not switch a command off. | Check the machine. See What happens when something fails. |
When a control in LineKeeper Go is greyed out, the caption under it says why:
| The caption | What it means and what to do |
|---|---|
Remote control is not set up on this device. An administrator assigns a key switch input in Settings → Hardware → Remote control. | No key is assigned. The button Open device settings opens the card. |
Turn the key switch to REMOTE on the device to control from this phone. | The key is at LOCAL. Turn it at the device. |
The device cannot read its key switch, so remote control is off. Check the key switch wiring (or the PLC connection, if the key is a PLC tag). | The key is unreadable. Check the wiring, or the PLC connection for a tag key. |
Remote control timed out. Turn the key to LOCAL and back to REMOTE. | The time limit ended. The other reasons start differently (The device restarted. …, Remote control was cancelled at the device. …, The remote control settings changed. …, The device changed its PLC connection. …, The key switch could not be read for a moment. …, A command could not be switched off. …) and end the same way. Turn the key. |
<name> is controlling this machine. | Someone else holds control. You can watch. They press Release control, or the window ends. |
Take control to send commands. | Press Take control. |
This phone is signed in as Viewer, which is read-only. Sign in as Operator or Administrator to control this machine. | Press Sign in and use an Operator or Administrator login. |
Enter a value from <min> to <max>. | The value is out of range. |
Another command is still running. | Wait for the running command. |
The device could not confirm that <label> was switched off. Remote control is blocked until it is. Check the machine. | Go to the machine. See What happens when something fails. |
Commands are never sent over a remote connection (Tailscale or a proxy). Use the plant network. | The phone is on Tailscale or a proxy. Join the plant Wi-Fi. |
The device is not connected to a PLC. | Connect the device to the PLC. |
The device could not write to the PLC: <message> | The PLC refused the write. Read the message. |
On this device <label> is a <mode> function. | The control does not match the function's mode. |
This tag is not on the device's remote control list. | The administrator has not added the tag to the list. |
Update LK On to control this machine from the phone. | The device software is older than this feature. Update it (section 16). |
If the phone has no Pro, taking control opens the Pro screen and nothing is sent.
20. Reading the status indicators
Top-right corner of the interface:
| Indicator | Meaning | What to do |
|---|---|---|
| 🟢 machine address | Connected, data is live | Nothing — carry on |
| 🟡 Reconnecting… | Connection dropped, restoring automatically | Wait; the machine keeps running its own program |
| 🟡 Data stale | Numbers on screen may be outdated | Don't act on them until it recovers |
| ⚪ Offline | Not connected to the machine | Connect on the PLC tab, or call the engineer |
Key safety fact: if the connection is lost, LineKeeper never switches anything on or off by itself. Momentary buttons release; the machine continues running its own program exactly as before. LineKeeper is not a certified HMI and not a safety device. The one exception is remote control behind a key: there the device itself writes the 0 that ends a command it started, and the PLC program must stop the machine when the device cannot (section 19).
21. Troubleshooting
Work top to bottom: power → network → connection → recording → display.
| Symptom | Check | Fix |
|---|---|---|
| Screen is dark | Tap it. Still dark? | Check the device's power supply and cable. |
| Can't open the interface from a browser | Is the computer on the same network? Is the address right? | Read the current address off the device's own screen (Settings → Wired network / Wi-Fi), or use the name http://linekeeper-XXXX.local:5000. Use http:// and port :5000, e.g. http://192.168.1.20:5000. |
| A Wi-Fi network LineKeeper-XXXX appeared on your phone | The device has lost every network connection and is waiting to be reconfigured | Join it (password linekeeper) and the setup page opens — pick the plant Wi-Fi again, or check the wired cable. |
| "Invalid password" at sign-in | Right role selected? (Operator and Administrator have different passwords.) | Administrator can change the other role's password in Settings. Lost administrator password → ./reset_password.sh engineer on the device console. |
| Connect fails on the PLC tab | Is the IP right? Slot (usually 0)? Can the device reach the controller — same subnet or route? Try Find PLCs. | Fix the wired-network address (Settings → Wired network) so the device is on the PLC's subnet. Check the cable and the machine's switch. Note: some plant firewalls block EtherNet/IP (TCP 44818), S7 (TCP 102) or Modbus (TCP 502). |
| Connected, but the tag list is empty | Modbus or Siemens S7? | Those protocols carry no tag names — paste a tag map in the connection form (the format is shown there). Logix, OPC UA and legacy Allen-Bradley list their tags or data files by themselves. |
| 🟡 "Reconnecting…" for more than a few minutes | Cable at the device and at the control cabinet; Wi-Fi status in Settings | Reseat cables; check the PLC is powered and reachable. The device keeps retrying by itself. |
| 🟡 "Data stale" | Usually recovers alone within seconds | If constant: the network path to the PLC is overloaded or flaky — check cabling/switches. |
| Panel button doesn't respond | The status pill (top right) | If not green — fix the connection first; writes are blocked while offline. If the message says the tag is locked, an administrator unlocks it once (Settings → Write access). |
| A phone or a browser cannot start a function; its controls are greyed out | The caption under the control says why. The key switch at the device must be in REMOTE and you must have taken control. | Section 19 lists every caption and what to do. Remote control works only on the plant network, never over Tailscale. |
| The device screen says This screen is not paired. | A remote control key is assigned and this screen has no pairing, so its writes are blocked. | An administrator pairs it at the device screen: section 19. |
| The wizard's "Find it by action" found nothing | Was the control pressed inside the countdown? | Press Start the presses over, wait for the resting-state phase to finish, then press the control as soon as it says Press it now. Some controls are wired to the panel, not the PLC — those have no tag to find. |
| Ladder shows grey tags | Tags not found on the connected controller | The export is older than the program running now — export a fresh .L5X and Replace file. |
| Alarm never fires | Is the tag under Settings → Recording and Active? Is the recorder Running? | Rules only see collected tags. Check the condition's direction and the min-duration setting. |
| Telegram / WhatsApp message never arrives | Settings → Notifications: is the channel Enabled? Does the device have internet (Wi-Fi)? | Re-run Detect chat ID for Telegram; for WhatsApp outside the 24-hour window, set a template. |
| No data in dashboards / "No data for period" | Settings → Recording: is the recorder Running? Is the tag in the list and Active? | Add the tag to collection on the PLC tab (recording starts by itself). If the period predates when collection began, there is simply no data for it yet. |
| Chart looks flat / too coarse | Widget ? button explains windows and aggregation | Raise Points, shorten the period, or reduce the tag's deadband under Settings → Recording (too big a deadband swallows real changes). |
| Counter widget shows less than expected | Did the PLC counter reset mid-period? | That's handled (resets aren't counted as negative). Check the period actually covers the shift — or use the dashboard-wide custom range. |
| Update seems to have broken something | Settings → Software Update | A failed update rolls back automatically and the update card says so. If the interface misbehaves after an update, do a hard refresh in the browser (Ctrl+F5). |
| The device is hopelessly misconfigured | Export config first if anything is worth keeping | Settings → Factory Reset returns it to the first-boot screen; passwords and network settings survive. |
| Anything else | System Logs: click the status pill, or Settings → System Logs | Read the last lines to your engineer or send a screenshot; that's usually enough to diagnose remotely. |
Operators: please don't change values on the PLC tab without instruction — use the Control Panel that was built for you.