The Linux Device Details page in the Workspace ONE UEM console shows options available for customizing your enrolled Linux devices. Use the Device Details page to review and modify user and device actions.
Device Details
You can access Device Details by selecting a device's Friendly Name from the Device List View, using one of the Dashboards, or with any of the search tools.
From the Device Details page, you can access device information broken into different tabs. Each tab contains related device information, which can vary depending on your Workspace ONE UEM deployment.
- Summary - View general statistics such as enrollment status, compliance, last seen, platform/model/OS, organization group, serial number, storage capacity, and physical memory. The Security Panel on the Summary page reports if a Linux device is encrypted and if a firewall is enabled.
- Encryption Detection - Workspace ONE UEM only detects devices encrypted with Linux Unified Key Setup (LUKS).
- Firewall Detection - Workspace ONE UEM shows enabled when firewalld or UFW services are running on the device.
- Profiles - Displays all profiles assigned to the selected device both installed (active) and assigned (inactive).
- Apps - Displays a list of installed desktop apps along with the app status, installation status, and assignment status.
- Sensors – View all sensors assigned to the selected device. This data includes the name, value, and last executed date.
- User - Access details about the user of a device and the status of the other devices enrolled to this user.
- Network – View current network (Wi-Fi) status of a device.
- Security - View the last received security information statuses from the device. The Security tab shows if a device is enrolled, if profiles are installed, and the status of certificates. The Security tab also shows the Disk Encryption Status for a device.
- Notes - View and add notes regarding the device. For example, note the shipping status or if the device is in repair and out of commission.
- Certificates – Identify device certificates by name and issuer. This tab also provides information about certificate expiration.
- Terms of Use - View a list of End User License Agreements (EULAs) which have been accepted during the device enrollment.
- Troubleshooting - View Event Log and Commands logging information.
- Status History - View history of device in relation to enrollment status.
- Attachments - Use this storage space on the server for screenshots, documents, and links for troubleshooting and other purposes without taking up space on the device itself.
The More Actions drop-down on the Device Details page is similar to same function on the list view, but with extra features. Perform remote actions over the air to the selected device using these actions. The actions available vary depending on factors such as the device platform, Workspace ONE UEM console settings, and enrollment status.
-
Query - This option submits an on-demand request for a device to send an updated sample data back to the Console. Selecting the Query option submits a request for all of the following. To request one of the items, access the More Actions menu.
- Device Information - Send an MDM query command to the device to return information on the device such as friendly name, platform, model, organization group, operating system version, and ownership status.
- Profiles – Send an MDM query command to the device to return a list of the installed device profiles.
- Certificates – Send an MDM query command to the device to return a list of the installed certificates.
- Sensors – Send an MDM query command to the device to return updated Sensor values.
-
Enterprise Wipe – This option unenrolls and removes any Wi-Fi and credentials that Workspace ONE UEM pushed down to the device and removes the Workspace ONE Intelligent Hub from the device. This option does not remove custom configuration profiles that are sent to the device, but it runs any defined removal manifests. See Custom Configuration profiles for more information.
-
Reboot Device - Send an MDM command to restart Linux devices remotely. This action reproduces the effect of powering device off and back on.
-
Device Wipe - Send an MDM command to clear all data from a device. This action emulates a factory reset on a Linux device.
Note: When the Device Wipe action is invoked by an administrator it cannot be undone.
This action removes apps, users, user files and data, Wi-Fi connections, and other items to make the device unusable, requiring a new install of Linux. The items removed by the Device Wipe action, include the following:
-
Remove user-installed apps - deb
-
Remove user-installed apps - rpm
-
Remove graphical environment apps – deb
-
Remove snap packages
-
Disable remote access to the machine (via SSH)
-
Cleanup cache data and temp files
-
Block user login
-
Remove all saved Wi-Fi connections
-
Delete users and home directories
Note: System users are not deleted. System users are excluded based on their UID.
-
-
Change Organization Group – Assign the device to a different existing organization group, with the option to choose either a static or dynamic OG.
-
Manage Tags – Assign a customizable tag to a device, which can be used to identify a special device in your fleet.
-
Edit Device – Edit device information such as Friendly Name, Asset Number, Device Ownership and Device Category.
-
Delete Device – Delete and unenroll a device from the Workspace ONE UEM console. This action performs an Enterprise Wipe and removes the device from the Workspace ONE UEM console.
Request Linux Device logs
Linux devices enrolled in Workspace ONE UEM support on‑demand log collection to assist with troubleshooting and advanced diagnostics. Administrators can remotely request Hub logs, system logs, or additional custom log files from a single Linux device. Requested logs are uploaded to the UEM console and made available in the device’s Attachments > Documents tab. This feature requires UEM version 2604 or later and is available for Linux devices running the Workspace ONE Intelligent Hub for Linux version 25.11 or later.
Prerequisites
- The device is enrolled and currently connected to Workspace ONE UEM.
- Workspace ONE Intelligent Hub for Linux 25.11 is installed on the device.
- You are viewing a single device. The Request Device Log command is not available when multiple devices are selected.
Access the Request Device Log command
-
Navigate to Devices > List View and select the Linux device.
-
Open the More Actions menu.
-
Under Admin, select Request Device Log.
If a previous log collection request is already in progress, the command is replaced by Stop Debug Logging until the earlier request completes or is manually stopped. Selecting Request Device Log opens a configuration window where you can customize what type of logs to collect and how they should be generated.
| Settings | Description |
|---|---|
| Source | Choose which category of logs to collect. |
| Hub | Collects log files generated by the Workspace ONE Intelligent Hub. These logs include enrollment activity, communication events, and Hub runtime behavior. |
| System | Collects standard Linux system logs from common locations such as /var/log/syslog and /var/log/messages(only if present on the device). |
| Additional | Allows you to specify a custom file path to collect additional log files or folders. |
| Additional Source | Supported File Extensions - .log, .txt, .out, .gzand file without any extension. While * can be used as a wildcard, the file must have a supported extension or no extension at all for the feature to function properly. Additionally, a valid custom path must conclude with a file that has one of the supported extensions. |
| Type | Defines how the logs are collected. |
| Snapshot | Issues a one minute delay and then captures and uploads the most recent log records available at the time of the request. |
| Timed | Collects logs over a rolling period of time with configurable duration and log level. Only available when Hub is selected as the source. Note: When System or Additional is selected, Timed appears but is disabled. |
| Duration | Visible only when Type = Timed. Choose how long the Hub should run detailed logging before packaging and uploading the collected logs. Available durations:
The default duration is 15 minutes. |
| Level | Visible only when Hub is selected and Timed is chosen. Defines the verbosity of Hub logging during the timed collection window:
|
| Log Name & Path (Additional Source Only) | If Additional is selected, use this field to specify which custom logs to collect. Examples:
|
- After configuring the options, select Save. The Hub receives the log request and, upon successful completion, uploads the resulting log bundle to Workspace ONE UEM.
Viewing collected logs
Once processed by the device, logs are available in Device Details > More > Attachments > Documents.
You can perform the following actions:
-
Download logs
-
View logs (where supported by device type and file format)
-
Delete logs
Uploaded logs are named according to the source and timestamp of collection.
Stop Debug Logging
If a Timed Hub log collection is in progress, the Request Device Log command is replaced with Stop Debug Logging in the device’s action menu.
Selecting Stop Debug Logging:
-
Immediately ends the active logging period.
-
Packages and uploads any logs collected up to that point.
-
Returns the Hub log level to the default setting.
For more information about this logging feature and configurability device side, see Command-line Utilities for Workspace ONE Intelligent Hub on Linux.
Was this page helpful?