Skip to main content

Entrosity Sphere

Entrosity Sphere is video management in the browser for network video recorders (NVRs) on your customers' networks: what a desktop client such as SmartPSS does, without installing anything on the viewer's computer. You watch cameras live, move PTZ cameras, play back what the NVR recorded, and follow and acknowledge the NVRs' alarms, for every site of a customer in one place.

Sphere runs at https://hub.entrosity.com/sphere. You sign in on Entrosity Hub, like for every Entrosity product, and open Entrosity Sphere from the Hub's product launcher.

Entrosity Sphere is in beta

Sphere is currently open to platform admins only: organizations and their users do not see it yet. A platform admin releases it to organizations under Products in beta.

What it does​

AreaWhat you get
Live viewCamera grids in the SmartPSS splits, from 1 to 64 tiles (2×2, one big + 5, one big + 7, 3×3 up to 8×8), and a single camera view. Grids use each camera's low-resolution sub stream, the single view its full-resolution main stream. Video plays in the browser over WebRTC.
PTZPan, tilt, zoom and focus while you hold a button, on the single camera page or for the selected tile of the live grid; go to and store presets (1–255); speed 1–8.
PlaybackSearch cameras' recordings on the NVRs (at most 7 days per search; segments marked continuous, motion, alarm or manual) and play up to 64 cameras side by side, in sync, from any moment, an hour at a time.
AlarmsThe NVRs' events (motion, video loss, alarm inputs, analytics such as line crossing) and the NVRs going online or offline, in one log, live and searchable. Operators acknowledge alarms one by one or everything up to a moment.
Saved viewsNamed camera grids: your own, or shared with everyone in the tenant.
NVR connectionsConnect to an NVR (Sphere stays signed in to it, receives its alarms and can show its video) or disconnect from it (signed out, its streams stop). Test an NVR to read its model, serial number, firmware and cameras again.
Works through outagesAlarms are kept on the connector's disk while the Internet is down and delivered later, in order and exactly once. The NVRs keep recording on their own disks whatever happens to Sphere.

Sphere does not record video itself: recordings stay on the NVR, and playback reads them from there.

Supported hardware​

Sphere drives Dahua NVRs and the many OEM NVRs built on the same firmware, through their HTTP CGI API (digest authentication) and RTSP (driver dahua). A built-in simulator (driver simulator) stands in for an NVR for trials and demonstrations.

How it reaches the NVRs​

The NVRs sit on the customer's network and are not reachable from the Internet. A Sphere connector, a Windows service on a computer on the same network, connects out to Sphere and does everything that has to happen next to the NVRs.

  • The Sphere web app (/sphere) is where people watch and manage cameras. It updates live.
  • The Sphere backend keeps the NVRs, cameras, alarms and saved views, decides what the connectors do, and decides who may publish or watch which video.
  • The connector stays signed in to each connected NVR, receives its alarms, and runs jobs: tests, PTZ commands, recording searches. When someone watches a camera, it pulls the camera's stream from the NVR over RTSP and publishes it, unchanged, to the media server. The site needs no inbound ports and no VPN.
  • The media server receives the streams and plays them to browsers over WebRTC. It asks the backend about every publish and every viewer: a connector may only publish video of its own tenant, and a browser needs a short-lived token for exactly the stream it plays.

A camera's stream is pulled from the NVR once, however many people watch it; it keeps running for a few minutes after the last viewer leaves (5 for sub streams, 2 for main streams), so switching back to it is quick.

What a site needs​

  • An always-on Windows computer on the NVRs' network for the connector (the computer of an Edge connector will do). See Connectors.
  • Outbound TCP 443 to hub.entrosity.com and TCP 8322 to media.entrosity.com from that computer. Nothing inbound.
  • The NVRs' HTTP port (80, or the HTTPS port) and RTSP port (554) reachable from the connector, and a user name and password on each NVR.
  • Upload bandwidth for the streams watched at the same time: each is uploaded once, whatever the number of viewers.

Viewers need a current browser and, besides HTTPS to hub.entrosity.com, outbound UDP or TCP 8189 to the server's public address for the video (the browser learns the address when it opens the stream).

Limits​

LimitDefault
Streams open at once per connector (live and playback)64
Full-resolution (main) live streams per NVR4
Playbacks per NVR4
Recording search7 days per search, 2,000 segments
One playback24 hours from its start (the app plays an hour at a time)
Channels per NVR256

At a limit, a live stream still running after its last viewer left stops to make room (the one unwatched the longest). When every stream at the limit is watched, the request is refused with stream_limit: close other streams first. The server's operators can change the first three (Running Entrosity Sphere).

H.265 streams

Most browsers cannot play H.265 (HEVC) over WebRTC. NVRs often encode the main stream in H.265 and the sub stream in H.264: grids then play, and a camera's single view may not. Set the main stream to H.264 on the NVR for cameras you need in full resolution. MJPEG streams cannot be relayed at all. Testing an NVR lists the channels concerned.

Concepts​

Tenants and sites​

A tenant is a customer organization: an organization on Entrosity Hub with Entrosity Sphere enabled, with the same ID. Everything in Sphere belongs to one tenant. A site is a location of the tenant; NVRs and connectors can belong to one.

Connectors​

A connector runs on a computer on a site's network and drives the NVRs it reaches. One connector can drive many NVRs. See Connectors.

NVRs and cameras​

An NVR is one recorder behind one connector, reached at its LAN address with a user name and password. Its password is stored encrypted and never shown again; the connector fetches it from Sphere when it signs in. Each channel of the NVR is a camera (channels count from 1, as on the NVR). A camera is shown with the name you give it, else the NVR's channel title, else Channel N. Cameras are created and removed as the NVR reports its channels.

Connected and disconnected​

Connect and Disconnect are how you log in to and out of an NVR (NVRs). A connected NVR is one Sphere stays signed in to: the connector checks it every 30 seconds, receives its alarms, and serves its video. A disconnected NVR is signed out: no alarms, no video, until you connect it again. The NVR's status is what the connector last reported:

StatusMeaning
Online (online)Signed in and answering.
Offline (offline)The NVR does not answer (address, ports, network).
Auth failed (auth_failed)The NVR refused the user name or password.
Unsupported (unsupported)The driver cannot drive this NVR.
Disconnected (disconnected)Disconnected on purpose.
Unknown (unknown)Not reported yet, or the connector is offline.

What to do for each: NVRs → Statuses.

Streams and viewers​

A live stream is one camera's main or sub stream, shared by everyone watching it. A playback is one viewer's own. Each open video tile is a viewer that keeps its stream alive; a live stream nobody watches stops after 5 minutes (a main stream after 2), a playback as soon as its viewer is gone (closed, or the page left).

Alarms​

An alarm is an event of an NVR: its code (the NVR's own, such as VideoMotion, VideoLoss, AlarmLocal, CrossLineDetection, or Sphere's NVROnline and NVROffline), whether it started, stopped or was a single pulse, the camera, and the time. The log keeps alarms for a year by default.

Signing in​

  1. Sign in on Entrosity Hub (https://hub.entrosity.com).
  2. Open Entrosity Sphere for your organization. You need a role in Sphere: Tenant admin, Operator or Viewer (Roles and permissions). Organization admins give roles on the Hub (Organization members).
  3. If you belong to several tenants, choose one (Choose a tenant); Switch tenant in the sidebar changes it.

The app is in English and Bulgarian; the language button in the header switches between them (the choice is shared with the Hub and the other products in this browser).

Finding your way around​

The sidebar shows the pages of your tenant. Pages your role cannot use are hidden.

Sidebar itemWhat it isPage
OverviewThe tenant at a glanceOverview
Live viewCamera grids, the single camera view, saved viewsLive view, PTZ cameras
PlaybackRecordings on the NVRs, on a timelinePlayback
AlarmsThe NVRs' events, live, and acknowledging themAlarms
NVRsNVRs, connecting to them, their camerasNVRs
ConnectorsConnectors and enrollment tokensConnectors
Tenant settingsDefault time zone, retentionTenant settings
SitesLocationsSites
Audit logWho changed whatAudit log

The menu under your name links to your account on the Hub (Manage account on Entrosity Hub), the Hub's products (All products, and Manage members for tenant admins) and signs you out (Sign out). Global admins also get an Administration area: an Overview of all tenants (NVRs online and failing, cameras, connectors, unacknowledged alarms and live streams, with the same counters per tenant), Connector releases (Connectors → Connector releases) and a global Audit log.

Statuses are coloured the same way everywhere: green for online, connected and done, blue for in progress, amber for pending or unknown, red for offline, refused or failed, grey for idle (disconnected). The Back button in the header returns to the previous screen.

In this section​

For operators of the server: Running Entrosity Sphere. For integrators: Sphere API, Sphere connector protocol and Sphere connector.