Exporting HMI Recipe Records to TIA Portal: KTP400 Guide

David Krause13 min read
HMI ProgrammingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

During prototype commissioning of a Siemens S7-1200 machine controlled by a KTP400 HMI, recipe data records are typically authored on the panel and written to PLC tags at runtime. When the integrator must mirror those production recipes back into the TIA Portal project (for documentation, version control, or migration to a new HMI image), the default approach of exporting a .csv file to a USB stick is often impractical: panels are frequently installed inside locked cabinets, behind doors, or in locations where a service engineer cannot easily reach the front USB port without partial disassembly.

This reference documents the supported Siemens workflows for retrieving recipe data records from a KTP400 (or any Comfort/Comfort-like HMI) and importing them into a TIA Portal project without physically swapping external media. The procedures cover:

  • ProSave recipe database backup over Ethernet (works on both Basic and Comfort panels).
  • TIA Portal V20 import/export of the configuration-side recipe database for WinCC Runtime Professional.
  • PN/PN-coupler and S7-1200 tag mirroring as a fallback when HMI-side export is not feasible.

The flow follows the same logic as Siemens' official FAQ on HMI project migration, where the recipe database is treated as a transferable binary object between the runtime and the engineering station.

Panel model check. The KTP400 family ships in two variants: KTP400 Basic (Basic Panels, WinCC Basic, 6" monochrome or 4" color TFT, article numbers 6AV2 123-2DB03-0AX0 and 6AV2 123-1DB03-0AX0) and the older KTP400 Comfort that exists only as a project-only designation. The procedures below apply to the Basic variant unless noted; for full TP-series Comfort panels (TP700/TP900/TP1200/TP1500/TP1900/TP2200) the recipe count, file location, and ProSave dialogs are identical, with larger quotas.

Prerequisites

Item Required value / version Notes
TIA Portal V15.1 or later (V17/V18/V20 recommended) V20 unlocks the Importing recipes into the configuration workflow referenced in this article.
HMI firmware KTP400 Basic ≥ V14.0.0.0 WinCC Basic recipe data records require firmware 14.0+ for *.dat database compatibility.
ProSave V14 SP1 or later (matches the TIA Portal version) Install from the TIA Portal Setup or from the WinCC DVD under Support.
Network Ethernet / PROFINET between PC and HMI Both devices must be on the same subnet; HMI Transfer mode enabled.
PLC S7-1200 (any firmware ≥ V4.2 recommended) S7-1500 also works; the S7-1200 firmware ≥ V4.4 supports the symmetric Get_Put access used in Method 3.
OS Windows 10 64-bit / Windows 11 ProSave on Windows 7 is no longer supported by TIA V18+.

Confirm the panel can be reached from the engineering station. From a Windows command prompt:

ping 192.168.0.10

(substitute the HMI's actual PROFINET IP). A successful reply within < 5 ms indicates the panel is online and reachable. If the request times out, verify the X1/X2 port assignment, the configured transfer mode, and any firewall rules blocking TCP/UDP ports 102, 443, and 5000.

Method 1 — ProSave Recipe Database Backup over Ethernet

ProSave is the official Siemens service tool that performs the same upload/download operations as the USB stick, but over an Ethernet link. It is the only method that recovers a live recipe database (all data records, all structure values, all date/time stamps) from a panel whose project is unknown or has been deleted from TIA Portal.

Step 1: Configure the PC/PG interface

  1. Open Control Panel → Set PG/PC Interface (the legacy 32-bit control panel shipped with TIA Portal).
  2. Select S7ONLINE (STEP 7) → TCP/IP → <your network adapter>.
  3. Set the access point S7ONLINE to the same adapter.

Step 2: Put the HMI in Transfer mode

On the KTP400 navigate to Start → Settings → Transfer (or use the operator button sequence Ctrl + Alt + Del equivalent on a touch panel: Start → Service → Transfer). Enable the transfer channel and note the IP address. If the panel was configured with Automatic transfer, it will already accept a project push from any source after a power cycle.

Step 3: Launch ProSave and select the panel

  1. Start ProSave from C:\Program Files\Siemens\Automation\Portal V20\Data\ProSave.exe (path varies with the TIA version).
  2. In the General tab, set Device type to KTP400 Basic color PN (or the exact article number visible on the back of the panel: 6AV2 123-2DB03-0AX0 for the color 4" Basic).
  3. Set Connection to Ethernet / PROFINET.
  4. Enter the HMI IP address; leave the default port 5000 unless the project explicitly changed it.
  5. Click Connect. ProSave should report Connection established in the status bar.

Step 4: Backup the recipe database

  1. Switch to the Recipes tab (in older ProSave builds the tab is labelled Recipe view).
  2. Click Backup (in some builds: Save as).
  3. Choose a target folder on the PC, e.g. D:\Recipes\KTP400_Project\2026-01-14\.
  4. Confirm. The recipe database is written to a single file with the panel's project name and the extension .dat. Typical filename: Recipe_Project_KTP400.dat.
File format note. The .dat file is a binary blob that ProSave/TIA Portal can re-load into any identically configured panel. It is not human-editable; to obtain a CSV view, use Method 2 or open the file in the TIA Portal Recipes editor after a restore.

Step 5: Restore or re-import into TIA Portal

  1. In TIA Portal, open the HMI device configuration and open the Recipes node.
  2. Right-click the recipe and choose Restore from backup (or drag the .dat onto the recipe entry). TIA Portal validates that the recipe structure matches the configuration; mismatched structures raise error 1900H: Recipe structure mismatch.
  3. Click Compile → HMI → Software (rebuild all) so the imported data records become part of the HMI image.

The same ProSave dialog can also be used to restore the recipe database back onto the panel after a factory reset, which is the symmetric reverse path: Recipes → Restore → Select .dat file.

Method 2 — TIA Portal V20 Configuration Import/Export

For WinCC Runtime Professional, TIA Portal V20 provides first-class CSV import/export of the configuration-side recipe database. This method does not require the HMI to be online; it operates on the engineering project directly. It is the fastest path when the same recipes must be re-deployed to several machines or when the recipe set is being documented as part of a recipe-management workflow.

The official V20 documentation is published at Importing recipes into the configuration and exporting them again.

Step 1: Open the Recipes editor

  1. In TIA Portal project tree, expand HMI → Recipes.
  2. Double-click the recipe to open the table editor (Structure / Elements / Data records tabs).

Step 2: Export existing data records

  1. Select the Data records tab.
  2. Click Data records → Export → CSV.
  3. Choose a target path. A *.csv file is created with the following structure:
Name;Version;Status;Date;Time;Author;Comment;Field1;Field2;Field3
DARK;1;OK;2025-11-04;14:21:08;Operator1;Line 1 dark theme;120;55;0
LIGHT;1;OK;2025-11-04;14:21:55;Operator1;Line 1 light theme;255;255;0

Subsequent columns are the recipe elements in the order defined in the recipe structure. The separator is locale-aware (semicolon in German/European locales, comma in US English); the export dialog reports the actual separator used.

Step 3: Import a CSV back into the configuration

  1. Edit the CSV in Excel or a text editor.
  2. Return to TIA Portal, Data records → Import → CSV.
  3. Select the file. TIA Portal validates each row against the recipe structure; incompatible types are flagged with a red marker and a tooltip explaining the violation (e.g. Field1 out of range 0..65535).
  4. Click Apply. The data records are merged into the project; existing records with the same Name + Version are overwritten.
Limitation. The V20 import/export workflow applies to WinCC Runtime Professional (PC-based HMI). On WinCC Basic (which runs the KTP400 Basic), the import path is the ProSave .dat workflow described in Method 1. The two paths are not interchangeable: a CSV exported from an RT Professional project cannot be directly read back into a Basic panel, and vice versa.

Step 4: Push the updated recipes to the panel

  1. Compile and download the HMI to the panel. The compile operation packages all data records into the runtime image.
  2. Alternatively, use Online → Recipe management → Download recipe data records only to push just the recipe data without recompiling the full project. This option is available with TIA V17+ and reduces panel downtime during commissioning.

Method 3 — Ethernet-Based CSV Export from the Panel Itself

When the cabinet is sealed but a network drop is available, the panel's built-in Export function can be re-pointed to a network share, eliminating the USB stick entirely. The mechanism is the same one Siemens describes for migration scenarios: the Storage location for recipe exports is configurable per recipe.

Step 1: Map a network share on the engineering PC

  1. Create a folder on the PC, e.g. C:\HMI_Recipe_Drop\.
  2. Share it as HMI_Recipe_Drop$ with read/write access for the panel account. The panel's User management credentials must match.
  3. Note the UNC path: \\192.168.0.50\HMI_Recipe_Drop$.

Step 2: Configure the export path in the recipe

  1. In TIA Portal, open the HMI recipe editor.
  2. For the recipe, set Properties → Storage location to \\192.168.0.50\HMI_Recipe_Drop$.
  3. Recompile and download the HMI project so the new path is active on the panel.

Step 3: Trigger the export from the panel

From the runtime recipe view, press Export. The panel writes a CSV directly to the share, and the engineer can pick it up from the PC without opening the cabinet.

Method 4 — Fallback: Mirror Recipe Data Through the S7-1200

If none of the above methods are available (locked-down panel, no ProSave license, mixed-protocol environment), the recipe data records can be reconstructed by reading the corresponding tags on the S7-1200. The S7-1200 retains the last values written by the panel, so a snapshot of those DBs effectively reproduces the recipe state at the moment of last write.

Step 1: Identify the recipe DB

Recipes on a Basic panel are stored in a fixed DB generated by TIA Portal, typically DB_RECIPES or the DB whose name matches the recipe (e.g. DB_Recipe_ColorMix). In TIA Portal, open Project tree → PLC_1 → Program blocks → System blocks → Recipe data blocks.

Step 2: Read the DB online

  1. In TIA Portal, expand PLC_1 → Watch & force tables.
  2. Create a watch table referencing every element of the recipe DB.
  3. Go online. The current values appear.
  4. Use Snapshot → Save as CSV to record the live state.

Step 3: Replay into the configuration

The captured values can be typed into a new data record in the TIA Portal Recipes editor. This is tedious for recipes with many elements and is therefore a last-resort method; reserve it for one-off recoveries when the HMI's own export channel is unavailable.

Caution. Reading the S7-1200 DB returns the last value the panel wrote, not the panel's persistent recipe database. If the operator has changed values but not yet written them to the panel, those uncommitted changes are lost. Always confirm with the operator that all recipes are saved on the panel before performing the DB read.

Troubleshooting Matrix

Symptom Likely cause Fix
ProSave: Connection failed (0xE001) Wrong device type or transfer not enabled on panel Verify the article number on the panel rating plate; enable Settings → Transfer on the HMI.
ProSave: Backup aborted (0xE013) Recipe database corrupted (power loss during write) Cycle the panel power, retry; if persistent, clear the recipe DB and re-load the project from TIA Portal.
TIA Portal import: 1900H Recipe structure mismatch CSV columns do not match the recipe element list Re-export a clean CSV from the same TIA Portal project; do not hand-edit headers.
Network share export returns 0xE402 Panel cannot resolve the host name or the credentials are wrong Use the IP-based UNC path; create a panel user whose name/password match the share ACL.
Watch table shows recipe tags greyed out Panel does not own the connection (area pointer not configured) Verify HMI → Connections → Area pointers → Recipe data points to the same DB.
Compiled recipe count differs between project and panel Panel holds an older image Perform a full download (not differential) from TIA Portal.

Verification

After any of the four methods, perform the following checks to confirm a successful transfer:

  1. File integrity: open the recovered .dat or CSV and confirm that the record count matches the panel's runtime display. On a Basic panel, navigate to Start → Recipes; the count of data records shown must equal the number of rows in the file.
  2. Structure check: re-import the recovered file into a clean TIA Portal test project. TIA Portal reports the import as successful only if every element type, every name, and every limit value match.
  3. End-to-end roundtrip: download the recovered recipes to a panel, perform a Save from runtime, then re-export. The two CSVs must be byte-identical (or differ only in the timestamp columns). This is the strongest field-proven validation.
  4. PLC cross-check: if the recipe drives PLC tags, switch each data record and confirm the expected tag value is written to the S7-1200. Use a watch table to observe the value at the moment the panel issues a Write to PLC command.

Field-Proven Notes

  • Firmware parity. ProSave must be the same major version as the panel's runtime image. Mixing a V16 ProSave with a V14 panel raises 0xE001 even when the connection is otherwise correct. Always check Panel → Start → System → Version before opening ProSave.
  • Recipe quota. KTP400 Basic supports up to 32 recipes with 32 elements each and 32 data records per recipe, and 256 KB of total recipe data. Comfort panels scale to 1000+ recipes and 4 GB. Confirm the engineering project stays within quota, especially when copying data records between machines.
  • Cabinet-free commissioning. On modern machines, the Engineering Station PC and the HMI are usually on the same managed switch. Configuring the export path as a network share (Method 3) is the lowest-friction workflow for ongoing engineering changes; the USB stick is reserved for situations where the network is intentionally air-gapped for cyber-security reasons.
  • Cybersecurity. When the recipe database contains proprietary process parameters (temperatures, pressures, setpoints for a paint line, etc.), restrict the ProSave backup folder with NTFS ACLs and encrypt the folder at rest. The CSV export shares the same sensitivity profile.
  • Version control. Commit recovered recipes to the project's \Recipe\<date>\ folder and reference the TIA Portal project revision that produced them. This is mandatory for ISO 9001 / GMP environments where recipe traceability is auditable.

Related Standards & References

The recipe-handling workflows described above are aligned with:

FAQ

Can I download KTP400 recipe data records to TIA Portal without opening the cabinet?

Yes. Use ProSave (Start → Programs → Siemens Automation → ProSave) with Connection = Ethernet/PROFINET, set the device type to the KTP400 article number visible on the back of the panel, connect, and run Recipes → Backup. The .dat file is written to the engineering PC over the network, no USB access required.

Does TIA Portal V20 import recipe CSV files on a KTP400 Basic?

The CSV import/export workflow documented in TIA V20 targets WinCC Runtime Professional (PC-based HMI). For KTP400 Basic, the supported import path is the ProSave .dat restore into a panel whose recipe structure already matches; CSV roundtrip is not supported on the Basic runtime.

What ProSave version should I use for a KTP400 Basic with firmware V14?

Use ProSave V14 SP1 or later, ideally matching the TIA Portal version used to build the project (V17, V18, V20). Mismatched major versions raise connection error 0xE001 on the backup operation.

How do I retrieve recipes when the HMI is unreachable on the network?

Read the recipe DB directly from the S7-1200 using a watch table in TIA Portal. The panel writes the active data record to the configured DB, so a snapshot of those tags reproduces the last-known recipe state. Note that uncommitted panel changes are lost in this scenario.

Can I point the HMI's export function to a Windows network share?

Yes. Configure the recipe's Storage location property in TIA Portal to a UNC path such as \\<PC>\<share>, recompile, and download to the panel. The operator's Export button then writes a CSV directly to the share, allowing the engineer to retrieve recipe data without physical access to the panel.

Back to blog