Configuring TIA Portal PEW Data into a WORD Array Safely

David Krause6 min read
SiemensTechnical ReferenceTIA Portal
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Treat PEW126 through PEW556 as 216 aligned peripheral words and map destination element i to byte address 126 + 2 × i. Select the read mechanism from the CPU family, required update timing, and hardware boundaries: individual direct reads suit selected addresses, while DPRD_DAT suits coherent areas belonging to one configured hardware component. Do not copy the range as one blind block until every address has been matched to the hardware configuration.

Range Definition and Array Capacity

The term peripheral word here means a 16-bit value read directly from the input peripheral address space. Because each word occupies two bytes, valid source addresses in this range advance by two: PEW126, PEW128, and so on through PEW556.

Word count = ((556 - 126) / 2) + 1
           = 216 words

Source byte address(i) = 126 + (2 × i), for i = 0...215

A zero-based destination therefore needs elements 0 through 215. A one-based destination needs elements 1 through 216. The source consumes 432 bytes in total, but that does not prove that all 432 byte positions belong to one device or one coherent data area.

Confirm the hardware assignment for every word before implementing the transfer. The requested endpoints may fall inside different modules, may cross slot boundaries, or may include unassigned addresses. If only selected words are required, create an explicit address map instead of treating the interval as a continuous device record.

Symptom Interpretation

Observed behavior Engineering interpretation Next check
An EW value remains unchanged during a faster cyclic task The code is reading a process-image snapshot rather than the peripheral input at that execution instant. Compare the process-image update cadence with the calling task.
Array elements are shifted or duplicated The loop probably increments a word address by one byte or applies the array lower bound incorrectly. Check that source addresses advance by two bytes per element.
A coherent transfer does not cover the requested interval The interval crosses hardware-component or consistency boundaries. Partition the source by configured module or slot.
A PEEK/POKE solution does not compile for the selected CPU The chosen access area or instruction form is not supported by that CPU and language combination. Use the CPU-specific instruction help and compile a minimal peripheral read.

The distinction between EW and PEW matters whenever update time or process-image size caused the symptom. Replacing one with the other without checking those two conditions can hide the real addressing problem.

Peripheral and Process-Image Mechanism

An EW access reads the input process image. That image is a buffered snapshot refreshed according to the configured execution model. A PEW access reads the peripheral input address when the instruction executes. The values can match during normal operation, but their acquisition times are not inherently the same.

For example, a cyclic task executing every 2 ms cannot obtain a new sample from an input image refreshed with a 40 ms main scan merely by reading EW more often. A direct peripheral read is required when the application needs the value at the faster task's execution point. The module's own conversion and bus-update behavior still limits how often genuinely new data becomes available.

The CPU configuration is the deciding record. A change to the process-image range also changes when data is sampled, so it is not interchangeable with direct access when acquisition timing is part of the requirement.

Repeated direct reads across several modules are sequential, not one atomic snapshot. When a module exposes a coherent multiword area, use its coherent-data transfer mechanism. Coherency applies to the configured area of that component; it does not make an arbitrary interval spanning several devices simultaneous.

CPU-Specific Transfer Selection

Condition Preferred method Constraint
S7-1500, selected peripheral words SCL or an applicable AWL implementation Compile against the actual CPU and block-access configuration.
Coherent data from one configured component DPRD_DAT Match the call to that component's configured coherent area; split the work when the requested range crosses components.
Peripheral output transfer DPWR_DAT This is the corresponding write operation and is not a substitute for reading inputs.

For S7-1200/1500 hardware-oriented calls, select the configured hardware identifier. The project hardware view, compiled instruction interface, and module consistency definition decide the required operands.

DPRD_DAT is appropriate when the destination structure represents one complete coherent hardware area. It is not a universal copier for unrelated addresses between PEW126 and PEW556. When the range starts inside one device and ends inside another, define one transfer per coherent area and handle any remaining individual words separately.

Transfer Procedure

  1. Inventory the source. List each configured input module, its starting byte address, ending byte address, data length, and coherent area. Mark gaps and addresses that are not part of the required dataset.
  2. Define the sampling requirement. Choose process-image access when one scan-consistent snapshot is required. Choose direct peripheral access when the calling task must read at its own execution point.
  3. Size the destination. Allocate 216 WORD elements only if every aligned word from PEW126 through PEW556 is required. Place the array as a static member when it belongs to an instance DB, then reference it symbolically where the CPU permits.
  4. Partition by hardware boundary. Create a transfer group for each module or coherent area. Do not combine two hardware identifiers or unrelated slots in one DPRD_DAT operation.
  5. Implement the mapping. For a word-by-word loop, calculate source byte address 126 + 2 × i and write it to destination element lower bound + i. For a sparse selection, replace the arithmetic range with an explicit address table.
  6. Place the call. Execute the transfer in the task whose cadence matches the sampling requirement. Avoid calling the same destination-writing routine from multiple tasks unless access is deliberately coordinated.
  7. Handle access failures. Evaluate the status supplied by any coherent transfer instruction. For individual reads, define application behavior for an inaccessible or unconfigured address rather than silently treating the previous array value as fresh data.

Store raw peripheral data as WORD when the requirement is bit-preserving acquisition. Apply signed interpretation, scaling, or engineering-unit conversion in a separate layer so that acquisition faults can be distinguished from conversion errors.

Verification Checks and Recurring Pitfalls

  1. Check 1: array capacity. Expect exactly 216 writable elements for the complete inclusive range.
  2. Check 2: first mapping. Force or stimulate the channel represented by PEW126; expect only the first destination element to follow it.
  3. Check 3: address stride. Test consecutive source words; expect destination elements to correspond to 126, 128, 130, with no one-byte shift.
  4. Check 4: task timing. When direct peripheral access is required, expect the read to execute in the selected cyclic task rather than wait for the next main-scan process-image refresh.
  5. Check 5: hardware partitions. Expect each coherent read to match one configured component and to report successful completion before its destination data is accepted.
  6. Check 6: final mapping. Stimulate the value represented by PEW556; expect destination index 215 in a zero-based array, or index 216 in a one-based array, to change without altering its neighbor.

Another common error is validating only the first address; that misses stride mistakes that accumulate across a 216-word mapping.

FAQ

How do I calculate the WORD array size for PEW126 through PEW556?

Use ((556 - 126) / 2) + 1. The inclusive range contains 216 aligned peripheral words.

How do I choose between EW and PEW in TIA Portal?

Use EW for the configured process-image snapshot. Use PEW

How do I read the range coherently with DPRD_DAT?

Call DPRD_DAT separately for each configured coherent hardware area. Do not pass the entire PEW126-to-PEW556 interval as one area when it crosses modules or slots.

How do I copy PEW values on an S7-1200?

Implement the loop in SCL and select a peripheral access form supported by the configured CPU. Confirm PEEK/POKE peripheral applicability in the CPU-specific instruction help and with a minimal compile before building the full 216-word loop.

How do I verify the last PEW is not shifted?

Change the input represented by PEW556 while monitoring the array. Expect index 215 for a zero-based array or 216 for a one-based array to follow the input, with the adjacent element unchanged.

Back to blog