Configuring Siemens WinCC V7.5 Cloud Connector for Tag Transfer

David Krause10 min read
SiemensTutorial / How-toWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring Siemens WinCC V7.5 Cloud Connector for Tag Transfer

Overview

Siemens WinCC V7.5 introduced the WinCC/Cloud Connector as an integrated runtime option that streams process tags from a WinCC station to a cloud platform such as MindSphere, AWS IoT Core, or Azure IoT Hub. The connector is implemented as a Windows service inside the WinCC runtime that subscribes to local tags through the built-in OPC UA server, buffers the values on disk, and forwards them to a configurable cloud endpoint using MQTT over TLS (port 8883).

The connector is exclusive to WinCC V7.5 and later service packs. Earlier versions (V7.3, V7.4, V7.4 SP1) cannot be retrofitted with the Cloud Connector without a project migration to V7.5 or higher. The official product announcement is published as Siemens support entry 109760739. For background on the architectural shift toward cloud-based plant data distribution, see the ISA InTech feature Using the Cloud to Store and Distribute Manufacturing Data.

Prerequisites

Before starting the configuration, verify the following engineering and runtime prerequisites:

  • WinCC V7.5 (or V7.5 SP1 / SP2) installed with the WinCC/Cloud Connector option activated in the setup.
  • Operating system: Windows Server 2016 (Standard/Datacenter) or Windows Server 2019; Windows 10/11 Enterprise LTSC is acceptable for engineering stations only.
  • SQL Server 2016 SP2, 2017, or 2019 for the WinCC archive database.
  • Activated WinCC Runtime license (RC 16k, RC 64k, RC 128k, RC 256k, RC 512k, RC PowerPack, or RC Client).
  • Cloud Connector runtime license (counted per tag stream per second).
  • TCP port 8883 outbound open to the target cloud broker (MQTT/TLS).
  • OPC UA server of WinCC enabled (default port 4840).
  • MindSphere tenant or equivalent cloud endpoint credentials and root CA certificate.

Architecture and Data Flow

The Cloud Connector sits between the WinCC tag manager and the external cloud. The data flow has four stages:

  1. Tag source: WinCC internal tags, structure tags, and tag groups defined in the WinCC Explorer.
  2. OPC UA bridge: The internal WinCC OPC UA DA server exposes selected tags at opc.tcp://<host>:4840.
  3. Cloud Connector service: Subscribes to OPC UA nodes, applies filtering and aggregation, and writes to a local SQLite buffer.
  4. Cloud broker: MQTT publish to MindSphere, AWS IoT, Azure, or a private broker. Topic naming follows wincc/v1/<assetId>/<aspect>/<variable>.

This staged design lets the connector survive network outages: when the MQTT link drops, data is queued on disk and replayed after reconnect, with no impact on the SCADA process.

WinCC V7.5 Installation Requirements

Use the official WinCC V7.5 setup media. During installation select:

  • WinCC V7.5 base package
  • WinCC/Cloud Connector add-on (under "Options")
  • WinCC/OPC UA Server (enabled by default in V7.5)

Minimum hardware sizing for a Cloud Connector runtime:

Component Minimum Recommended (≤ 5,000 tags)
CPU Intel Xeon E3 / 4 cores @ 2.4 GHz Xeon E-2200 / 8 cores @ 3.0 GHz
RAM 8 GB 16 GB ECC
Disk (system) 80 GB SSD 240 GB SSD
Disk (buffer) 10 GB 50 GB (depends on retention)
Network 100 Mbit/s 1 Gbit/s with QoS

Do not co-locate the Cloud Connector on a domain controller or on a station hosting the WinCC WebNavigator if tag counts exceed 10,000.

Configuring the OPC UA Server in WinCC

The Cloud Connector relies on the internal OPC UA server. Verify it is enabled and that the tags you want to stream are exposed.

  1. Open WinCC Explorer, right-click Tag Management, select OPC UA Server.
  2. Tick Activate OPC UA Server. Default endpoint: opc.tcp://<hostname>:4840.
  3. Set Security Policy to None only for local-loopback connectors; for production select Basic128Rsa15 or Basic256Sha256.
  4. Under Tag Selection, add the tag groups or individual tags that should be visible to the connector. Avoid streaming raw archive tags; only stream runtime variables.
  5. Click Test Server to confirm the endpoint starts.

Cloud Connector Configuration

The Cloud Connector is configured from Start → Siemens Automation → WinCC → Cloud Connector, or by editing the configuration file directly:

C:\Program Files (x86)\Siemens\Automation\WinCC\CloudConnector\CloudConfig.xml

A minimal configuration for MindSphere looks like:

<CloudConfig>
  <Endpoint type="MindSphere">
    <Tenant>my-tenant</Tenant>
    <AssetId>wincc-station-01</AssetId>
    <AspectName>Production</AspectName>
    <Region>eu1</Region>
  </Endpoint>
  <Transport>
    <Protocol>MQTT/TLS</Protocol>
    <Port>8883</Port>
    <QoS>1</QoS>
  </Transport>
  <Buffer>
    <Path>D:\WinCC\CloudBuffer</Path>
    <MaxSizeMB>2048</MaxSizeMB>
  </Buffer>
</CloudConfig>

For AWS IoT Core or Azure IoT Hub, replace <Endpoint> with the corresponding broker type and provide the device certificate or SAS token path. The connector stores certificates under %ProgramData%\Siemens\CloudConnector\certs\.

Tag Mapping and Filtering

Tag mapping is done in the Cloud Connector UI under Tag Mapping. Each OPC UA node must be mapped to a cloud-side aspect variable. Mapping rules:

  • Variable name: alphanumeric, max 64 characters, no leading digit.
  • Data type: BOOLEAN, INT32, INT64, FLOAT32, FLOAT64, STRING (UTF-8).
  • Scan rate: 100 ms, 500 ms, 1 s, 5 s, 10 s, 30 s, 60 s.
  • Deadband: only publish when the value changes by more than ±N engineering units (recommended for FLOAT types to reduce cloud cost).
  • Quality code: include OPC UA StatusCode in the payload so consumers can detect bad / uncertain values.

To reduce cost and noise, group tags by aspect (e.g. Production, Energy, Quality) and assign different scan rates. Tag count limits per license tier:

License Tags / scan cycle Max scan rate
Cloud Connector 100 100 100 ms
Cloud Connector 500 500 100 ms
Cloud Connector 2000 2,000 500 ms
Cloud Connector 10000 10,000 1 s

Cloud Endpoint Setup

MindSphere (Siemens Insights Hub)

  1. Create a MindSphere tenant and an Asset / Aspect model via the MindSphere APIs or the Developer Cockpit.
  2. Generate a Service Credential with the role mdsp:core:asset.readwrite.
  3. Download the MindSphere root CA (X.509 PEM) and copy it to the connector's certs folder.
  4. Enter the tenant name, asset ID, and aspect name into CloudConfig.xml.
  5. Restart the Siemens Cloud Connector Service.

AWS IoT Core

  1. In the AWS IoT console, register a Thing and download the device certificate, private key, and Amazon Root CA 1.
  2. Attach a policy allowing iot:Connect, iot:Publish to the topic wincc/v1/+/+/+.
  3. Set <Endpoint type="AWS"> and point to the credential files.

Azure IoT Hub

  1. Create an IoT Hub and a device identity using the Azure CLI.
  2. Copy the device connection string (or SAS token) into <Endpoint type="Azure">.
  3. Ensure the IoT Hub accepts MQTT over TLS on 8883.

Buffering and Offline Behavior

The connector maintains a circular SQLite buffer on local disk. Key behavior:

  • Buffer size is controlled by <MaxSizeMB>. When full, oldest records are overwritten.
  • On reconnect the connector republishes buffered records starting from the last acknowledged sequence number.
  • Buffer flush is asynchronous and does not impact WinCC runtime cycle time.
  • Recommended disk type: SSD with at least 5,000 IOPS; mechanical disks cause write stalls under burst load.
Do not place the buffer on the same physical disk as the WinCC archive database when tag counts exceed 5,000 with sub-second scan rates. Use a dedicated volume.

Runtime Activation and Verification

  1. Open WinCC Explorer and start the project runtime.
  2. Verify the WinCC OPC UA server responds: from a PowerShell prompt run Get-OPCUAServer -Endpoint opc.tcp://localhost:4840 (requires the UaExpert CLI or PowerShell OPC UA module).
  3. Start the Cloud Connector service manually first to capture logs:
    net start "Siemens Cloud Connector Service"
  4. Open the Cloud Connector Diagnostic window (CloudDiag.exe in the install folder). Confirm:
    • State = Connected
    • Tags mapped matches the count in the mapping table
    • Publish rate / sec > 0
    • Queue depth remains stable (does not grow over time)
  5. On the cloud side, validate incoming messages via:
    • MindSphere: MindSphere APIs → Time Series → Read
    • AWS IoT: MQTT Test Client subscribed to wincc/v1/#
    • Azure IoT: Device Explorer / VS Code Azure IoT Hub extension

Security and Certificates

The connector supports X.509 mutual TLS. Configuration items:

  • Device certificate: must include Client Authentication in the Extended Key Usage extension.
  • Private key: stored in PKCS#12 (.pfx) or PEM with passphrase.
  • Root CA: must be added to the Windows certificate store under Trusted Root Certification Authorities on the connector host.
  • Topic ACLs: apply least-privilege rules to the device on the broker side. WinCC publishes to wincc/v1/<asset>/<aspect>/<variable>; do not grant wildcard subscribe to downstream consumers.

The local OPC UA server should run with Basic256Sha256 and an authenticated session for any non-localhost consumer.

Performance and Sizing Guidelines

Sustainable publish throughput depends on payload size, TLS handshake caching, and broker round-trip time. Field-tested values on a Xeon E-2236 with 1 Gbit/s link:

Scan rate Tag count Avg CPU Avg publish latency
100 ms 500 6 % 45 ms
500 ms 2,000 9 % 80 ms
1 s 5,000 12 % 110 ms
5 s 10,000 8 % 140 ms

Recommendations when scaling:

  • Aggregate fast-changing tags at the WinCC side (e.g. compute rolling averages) before publishing.
  • Use deadband filtering for analog process variables to cut MQTT traffic by 60-90 %.
  • Enable QoS 0 for non-critical tags; reserve QoS 1 or 2 for safety-relevant or alarm states.
  • Monitor queue depth in CloudDiag.exe; sustained growth indicates broker-side throttling.

Migration from WinCC V7.3 / V7.4

Projects on V7.3, V7.4, or V7.4 SP1 cannot be patched in place to add the Cloud Connector. Migration path:

  1. Back up the project database.
  2. Install WinCC V7.5 on the target machine (can coexist on a different host during cut-over).
  3. Open the project in V7.5; the setup wizard migrates graphics, scripts, and archives.
  4. Re-apply custom C / VB scripts as some legacy API calls were deprecated.
  5. Validate tag integrity with the Project Migrator Doctor tool.
  6. Install the Cloud Connector option and re-create the mapping.

Comparison: WinCC V7.5 Cloud Connector vs WinCC Unified

Feature WinCC V7.5 Cloud Connector WinCC Unified (TIA Portal V16+)
Cloud target MindSphere, AWS, Azure, generic MQTT MindSphere / Insights Hub, Industrial Edge
Transport MQTT over TLS, OPC UA DA MQTT over TLS, OPC UA Pub/Sub
Tag capacity Up to 10,000 (license tier) Up to 30,000 (RT Advanced / RT Professional)
Configuration UI WinCC Explorer + Cloud Connector plugin TIA Portal, fully integrated
Edge integration Not native Industrial Edge connector apps
Web client Requires WebNavigator add-on Built-in HTML5 client

Choose WinCC V7.5 for retrofitting existing SCADA plants with minimal change. Choose WinCC Unified for greenfield projects where TIA Portal is the engineering standard and the cloud-first design fits the plant architecture.

Troubleshooting Matrix

Symptom Likely cause Action
Service does not start License missing or expired Check License Analysis in Automation License Manager
State = Connecting forever Firewall blocks 8883 outbound Test with Test-NetConnection broker -Port 8883
Tags mapped = 0 OPC UA server not exposing tags Verify Tag Management → OPC UA Server selection
Publish rate = 0 with tags mapped Deadband filter blocks all updates Set deadband to 0 on a test tag
Queue depth growing Broker throttling or DNS failure Check CloudConnector.log for return codes 4 (quota) or 5 (auth)
TLS handshake fails Wrong CA chain installed Replace with full chain, include intermediates
MindSphere 401 Unauthorized Service credential expired Regenerate MindSphere service credential
Azure IoT device 404 Device disabled in IoT Hub Re-enable the device in Azure portal
High CPU in runtime Scan rate too aggressive for tag count Increase scan interval or enable deadband
Buffer overflow warnings MaxSizeMB too small for outage window Raise buffer size or move to faster disk

Field-Proven Caveats

  • Cloud Connector does not publish WinCC archive values directly; only runtime tag values. Archive data must be exposed via a separate ODBC or REST path.
  • If the WinCC project is renamed after Cloud Connector setup, the OPC UA node IDs change. Re-create the mapping table.
  • Antivirus scanning on the buffer directory can introduce delays; exclude the buffer path from real-time AV inspection.
  • Windows time skew greater than 30 seconds causes MindSphere to reject time-series records with HTTP 400. Enable NTP on the connector host.
  • Domain controller failover events may restart the connector service; configure the service recovery options in services.msc to auto-restart.

FAQ

Can WinCC V7.3 or V7.4 use the Cloud Connector?

No. The Cloud Connector was introduced with WinCC V7.5 and is not available in V7.3, V7.4, or V7.4 SP1. Upgrade to V7.5 (or later) and migrate the project using the standard WinCC project migrator.

What cloud platforms does the WinCC Cloud Connector support?

Out of the box it supports MindSphere (Siemens Insights Hub), AWS IoT Core, and Azure IoT Hub. Any MQTT v3.1.1 / v5 broker with mutual TLS can be configured by editing CloudConfig.xml.

Does the Cloud Connector require a separate OPC UA configuration?

Yes. The connector subscribes to tags through the internal WinCC OPC UA DA server. Activate the server in WinCC Explorer and add the desired tags under OPC UA Server → Tag Selection.

What happens when the cloud connection drops?

The connector writes incoming samples to a local SQLite buffer (default path D:\WinCC\CloudBuffer) up to MaxSizeMB. When the link is restored, buffered records are replayed in order to the broker. If the buffer fills, oldest records are overwritten first.

How many tags can the Cloud Connector stream?

Capacity depends on the license: 100, 500, 2,000, or 10,000 tags per scan cycle. Higher tag counts and sub-second scan rates require a larger license tier and dedicated CPU/disk resources as shown in the sizing table above.

Back to blog