Everyday Operation of SIWENOID v2
This page describes the daily operational use of SIWENOID v2 from the operator's perspective. It covers the event categories bar, the signal log and all its controls, how to handle alarms step by step, how to use the event log for searching and filtering, and how to export event data.
This page is relevant for both operators performing daily monitoring duties and engineers who need to understand how the operator interface functions in order to configure it correctly.
Prev ← Creating Module Next → System Preferences and Engineering Options
The Event Categories Bar
The event categories bar is displayed at the top of the SIWENOID v2 main screen at all times. It is always visible regardless of the workspace panel arrangement and cannot be hidden. It provides an immediate overview of the number of active and unacknowledged events across all event categories.
Every signal, event, and alert from every connected subsystem is sorted into one of the configured event categories. The categories bar shows each category as a labelled button with a background colour matching that category's configured colour. The same colours are used consistently in the signal log, event log, and on maps — so an operator who associates red with fire alarms will see red used for fire alarm events throughout the entire interface.
The “Normal” status is never shown in the event categories bar. Normal represents the idle state of a datapoint and is not considered an active event requiring operator attention.
Category bar elements:
1 — Event categories Each category button shows the category name and the count of events in that category in the format: acknowledged / total. For example, “0/1” in the Fault category means there is one fault event and it has not yet been acknowledged.
2 — Hidden event category An operator can hide all events belonging to a specific category from the signal log by clicking the category name button. Hidden categories are displayed with a transparent background in the categories bar. Events from hidden categories remain in the system and can still be bulk acknowledged from the category bar — they are simply not shown in the signal log view. The Alarm category cannot be hidden under any circumstances.
This feature is useful during maintenance — for example, when servicing a fire alarm panel that has many detectors in “Excluded” state, hiding the Exclusion category prevents it from cluttering the signal log while the real alarm events remain clearly visible.
3 — Bulk acknowledge button Each category has a bulk acknowledge button. Clicking it acknowledges all currently unacknowledged events in that category simultaneously. This is useful when a single incident generates many simultaneous events — for example, when a deactivated zone causes all its detectors to signal at once. Bulk acknowledgement is a software-only action: no commands are sent to any connected subsystem.
4 — Acknowledged / Unacknowledged count The counter on each category button shows the number of acknowledged events versus the total number of active events in that category (acknowledged/total). This allows operators to see at a glance how many events still require attention.
The Signal Log
The signal log is the primary monitoring interface in SIWENOID v2. It displays every active event from every connected subsystem whose current status is different from normal. This includes alarms, faults, exclusions, tamper conditions, communication errors, and any other non-normal status defined in the treatment configuration.
On a live site, the signal log is rarely empty. Larger installations always have some detectors excluded for maintenance, zones in test mode, or minor technical faults that are being tracked. The signal log is designed to make the most critical events — alarms — immediately visible at the top of the list regardless of how many lower-priority events are present.
All entries in the signal log are colour-coded with the background colour of their event category. Alarm events (typically red) are always sorted to the top of the signal log so they cannot be overlooked among a list of lower-priority events. If a category is hidden using the categories bar, its events are not displayed in the signal log.
Signal log columns:
- 1 — Category icon — the icon configured for the event's category.
- 2 — Timestamp — the exact date and time the event was received by the SIWENOID v2 server.
- 3 — Physical container — the name of the physical subsystem container the signalling datapoint belongs to (for example: the panel name or subsystem name).
- 4 — Datapoint name — the name of the datapoint that generated the event, as configured in SIWENOID v2.
- 5 — Status description — a description of the event status. For example: “ALARM”, “FAULT”, “CLIENT DISCONNECTED”, “EXCLUDED”.
- 6 — Acknowledgement state — new, unacknowledged events have a blinking background. Once acknowledged, the blinking stops. Events that have returned to normal but have not yet been dismissed are shown with a black (inverted) background.
Signal log action buttons (per event row):
- 7 — Default command button — sends the most appropriate command for this event type to the connected subsystem. The default command is predefined by the subsystem driver based on the datapoint type (for example: Reset for a fire alarm zone, Disarm for an intrusion partition). If no default command is applicable for this event type, the button is disabled. Right-clicking the disabled button still shows the full list of available commands for the datapoint.
- 8 — Show on map button — opens the map on which this datapoint is placed and highlights the datapoint's icon on that map. The button background is green when the datapoint is placed on at least one map. If the datapoint is not on any map, the button is grey and non-clickable. After opening the map, the datapoint icon blinks briefly with the event category colour.
- 9 — Intervention text button — opens the intervention text assigned to this datapoint. The intervention text is a predefined procedure or instruction that guides the operator on how to respond to this type of event (for example: “This zone cannot be reset while the windows are open.”). The button is grey and non-clickable if no intervention text is assigned to the datapoint. SIWENOID v2 can be configured to display intervention texts automatically when certain event types are received.
- 10 — Write comment button — opens the comment dialog for this event, allowing the operator to add a free-text note. Comments are permanently attached to the event record and are visible to all operators. Multiple comments can be added to a single event by multiple users.
- 11 — Show in hierarchy button — navigates the Datapoint Hierarchy panel to the signalling datapoint and selects it, displaying its full information, status, and command panels.
Deleted Events: Black Background Entries
Events displayed with a black (inverted) background in the signal log represent conditions that were active at some point but are no longer present at the time of viewing. The datapoint has returned to normal, but the event remains in the signal log to ensure the operator does not miss it.
These inverted entries can be dismissed from the signal log with a single click — clicking them acknowledges and removes them from the active signal log view. The event remains permanently in the event log.
Inverted background events appear in the following situations:
- The physical security system or the operator at the panel acknowledged or reset the alarm directly on the hardware, without the SIWENOID v2 operator doing so. SIWENOID v2 detected the return-to-normal signal and shows the event as resolved but not yet seen.
- Another SIWENOID v2 operator on a different client workstation acknowledged the event first, and multi-client acknowledgement synchronisation is configured in the system.
This mechanism ensures that operators always have a record of every event that occurred during their session, even if the physical condition was resolved independently of the software.
Handling Alarms — Step by Step
When an alarm or other significant event arrives, it appears in the signal log with a blinking background and (if configured) an audible alert. The following procedure describes the standard alarm handling workflow:
Step 1 — Acknowledge the event in SIWENOID v2
Click on the event row in the signal log to acknowledge it. The blinking stops and the audible alert for this event ceases. Acknowledgement is a software-only action — no command is sent to the physical security system at this point.
Alternatively, use the bulk acknowledge button in the category bar to acknowledge all events in the category at once, if multiple simultaneous events have arrived from the same incident.
Step 2 — Review available information
Before taking physical action or sending commands to the subsystem, use the available tools:
- Press button 8 (Show on map) to open the site map and see the physical location of the alarming datapoint. The datapoint icon will blink on the map to indicate its position.
- Press button 9 (Intervention text) to read the predefined response procedure for this datapoint, if one has been configured.
- Press button 11 (Show in hierarchy) to open the Datapoint Hierarchy and review the datapoint's recent event history and current technical status.
Step 3 — Write a comment (if required)
Press button 10 (Write comment) to open the comment dialog and record any relevant information about this event — for example, the cause of the alarm, who was notified, or what physical action was taken.
The comment dialog shows:
- 1 — Timestamp column — the date and time of each existing comment.
- 2 — User — the username of the operator who wrote each comment.
- 3 — Comment — the text of each existing comment.
- 4 — Text area — the input field for writing a new comment.
- 5 — Send button — saves the text from the input field as a new comment on this event.
Multiple comments can be added to a single event by any number of users. Comments are displayed in chronological order and are stored permanently in the event log.
Step 4 — Send a command to the subsystem (if required)
After reviewing the situation and documenting the response, send the appropriate command to the connected security system using button 7 (default command) or by right-clicking to access the full command list.
Using the Event Log
The event log contains a permanent, undeletable record of every event, signal, command, and operator action recorded by SIWENOID v2 since the system was commissioned. It can be searched and filtered by date, time, event type, and datapoint name, and the filtered results can be exported or printed.
Filter controls:
- 1 — Start date — filters the event log to show only events from this date onwards (from 00:00:00 on the selected date).
- 2 — End date — filters the event log to show only events up to and including this date (until 23:59:59 on the selected date).
- 3 — Start time — filters events to those that occurred after this time of day. If no start and end dates are set, this filter applies across all days — showing events from every day that occurred after this time.
- 4 — End time — filters events to those that occurred before this time of day. Combined with the start time, this creates a daily time window filter. For example, setting start time 10:00 and end time 15:00 with a specific date range shows only events that occurred between 10:00 and 15:00 on each day in the range.
- 5 — Event type — filters by event status type. Partial text matching is supported — entering “alar” will match all events with “ALARM” in their status name.
- 6 — Load saved filter — loads a previously saved filter configuration from the dropdown list.
- 7 — Save current filter — saves the current filter configuration with a custom name for quick recall. After clicking, enter a name and press Enter to save. Example: “Morning alarms 06:00–09:00”.
- 8 — Delete saved filter — deletes the currently loaded saved filter. Only active when a saved filter is loaded.
- 9 — Datapoint name filter — filters by the name of the datapoint. Partial text matching is supported — entering “p” will match all datapoints whose name contains the letter p (for example: “PIR 1”, “Panic Button”).
- 10 — Event status filter — filters by the specific status name of events (the treatment label). This allows filtering for specific status types within a category, such as “Communication disabled” or “Client connected”.
- 11 — Export button — exports the currently filtered event list to a selected file format.
- 12 — Print button — prints the currently filtered event list to the default printer configured in system preferences.
- 13 — Reset filters button — clears all active filters and returns the event log to its full unfiltered view.
- 14 — Results summary — displays a description of the current filter state and the number of matching events found.
Note: Both the export (11) and print (12) buttons require a start date (1) and end date (2) to be set before they become active. This requirement exists because on large installations the event log may contain millions of entries — exporting or printing without a date range would generate an impractically large file or printout.
Special Filter Modes: AND / OR Search
The text filter fields in the event log support two search modes that allow more precise filtering:
OR search (broader results) Enter multiple words separated by a space in any filter field. The filter returns all events that contain any one of the entered words. For example, entering “Alarm Normal” in the event type field returns all events with status “ALARM” or status “NORMAL”.
AND search (narrower results) Enter multiple words separated by the & character. The filter returns only events that contain all of the entered words simultaneously. For example, entering “Alarm & Normal” returns only events whose status contains both “Alarm” and “Normal” at the same time — which in practice returns no results, since a datapoint cannot be in both states simultaneously. This mode is useful for filtering datapoint names that share common words, for example: “door & main” to find only the “Main door” datapoint among many doors.
Exporting the Event Log
Click the export button (11) in the event log filter bar to export the currently filtered event list. A format selection dialog appears with three options:
- CSV — comma-separated values file, compatible with any spreadsheet application or database import tool. Best choice for further data processing or importing into other systems.
- XLSX — Microsoft Excel spreadsheet format. Best choice for operators who will review or present the data in Excel.
- HTML — an interactive, self-contained web page that can be opened in any browser without additional software. The HTML export includes filtering and sorting functionality within the page itself, making it useful for sharing event reports with people who do not have access to SIWENOID v2.
After selecting the format, a file save dialog opens. Enter the desired file name and location, then click Save to complete the export. Click Cancel to abort.
The same date range requirement applies to exports as to printing — a start date and end date must be set before the export button is active.
When printing or exporting large event logs, consider the volume of data carefully. On busy installations, a single day's event log can contain tens of thousands of entries.
—
Prev ← Creating Module Next → System Preferences and Engineering Options








