Fixing PLC Alarm Timestamp Mismatch on TP1500 Comfort with S7-400
Siemens S7-400 CPUs (including the F-variant CPU 416F-3 PN/DP) stamp every alarm, diagnostic buffer entry, and SFB/SFC message with a time value. When a SIMATIC TP1500 Comfort panel receives that alarm, the stamp is re-rendered in the HMI's local time zone. If the two devices do not share a common time base, the alarm view shows times that drift, jump, or are simply wrong relative to wall-clock reality. This article documents the root cause, the standard Siemens remedies (NTP, area pointer, master/slave), and a verification procedure that an automation engineer can execute in a live plant.
1. Problem Description
The reported installation has the following behavior:
- Several HMI screens show different system times, none of which match the current time.
- PLC error alerts on those screens inherit the wrong time, so the alarm log cannot be trusted for incident review.
- The operator must manually correct the time on each screen to get a sensible alarm history.
This is a classic symptom of an HMI that has never been told where the correct time comes from. The panel's onboard RTC (real-time clock) drifts at roughly ±20 ppm, which is about ±1.7 seconds per day, and accumulates to several minutes per month without a correction source.
2. Root Cause Analysis
Comfort Panels receive a UTC time stamp with every PLC alarm. The panel then converts the UTC value into the configured local time zone for display. Two failure modes are possible:
| Failure Mode | Mechanism | Symptom |
|---|---|---|
| Drift | Both clocks run freely without correction | Alarm time slowly diverges from wall clock; grows ±1.7 s/day per uncorrected RTC |
| Offset | PLC and HMI are set to different time zones or the HMI local time is not derived from the PLC UTC | Alarm time is consistently off by hours, or DST transitions are missed or doubled |
From the case, the S7-400 has its clock synchronization type set to Slave in the hardware configuration, but no master (NTP server, master clock, or another CPU) has been bound to it. The HMI connection has HMI time synchronization disabled. The panel therefore relies entirely on its own RTC, which has not been set or has drifted.
3. System Identification
| Item | Reported Value | Notes |
|---|---|---|
| Engineering | TIA Portal V16 | Project file is V16; HMI image is older (see below) |
| PLC | SIMATIC S7-400, CPU 416F-3 PN/DP (F-CPU) | Used as PROFINET proxy; F-variant implies a fail-safe program is present |
| HMI | SIMATIC TP1500 Comfort V2, 15.4" TFT, 1280×800 | 6AV2 124-1QCxx family |
| HMI OS | Microsoft Windows Embedded CE 8.0 (Build 6247) | About 800 MB free RAM at runtime |
| HMI Image | V15.01.00.02_04.01 | WinCC Comfort/Advanced V15.1 image, not the V16 image |
| Processor | AMD SteppeEagle (Geode class) | Standard for the Comfort V2 generation |
| Time sync | None active | PLC is an unmastered Slave; HMI sync disabled in the connection |
4. Reference Architectures
Siemens supports three viable time-synchronization paths between an S7-400 and a Comfort Panel. Pick one; do not mix them.
4.1 External NTP master (preferred for plants)
Figure 1 — Both devices take NTP from the same master, eliminating drift and offset.
4.2 PLC as NTP server (no plant NTP available)
Figure 2 — The S7-400 acts as the NTP source for the Comfort Panel. Documented in Siemens support entry ID 82203451.
4.3 Area pointer time master/slave (no NTP at all)
Figure 3 — The CPU pushes time to the panel via the Date/Time or Coordination area pointer. No NTP required.
5. Solution Path 1 — NTP on Both Devices (recommended)
This is the standard Siemens-recommended path. See Siemens support entry ID 82203451 for the canonical S7-400-as-NTP-server procedure and the complementary entry ID 69864408 for the overall time-synchronization concept.
5.1 Configure the S7-400 as NTP client
- Open the S7-400 station in TIA Portal V16.
- Select the CPU 416F-3 PN/DP, then open Properties → Time of day.
- Set Time synchronization type to NTP.
- Under NTP server, add up to four IPv4 addresses (plant master clock, GPS receiver, or stratum-2/3 server). Use a server reachable on the PN subnet.
- Set Update interval to a value appropriate for accuracy needs:
Use Case Recommended Interval Notes Sub-second audit trail 10 s Highest load; reserved for safety event recording Standard plant use 60 s Default choice; well within S7-400 RTC accuracy Office / low-priority 3600 s Minimizes network traffic; drifts up to ±1 s between syncs - Compile (Hardware) and download to the CPU.
5.2 Configure the S7-400 as NTP server (optional, when no plant NTP exists)
If the S7-400 has no upstream NTP source but is set to an accurate time manually (or from a GPS serial feed), it can serve time on its PROFINET interface. The procedure is documented in entry 82203451. Typical parameter values:
| Parameter | Value | Notes |
|---|---|---|
| S7-400 PN IP (in this case) | e.g. 192.168.0.10 | Becomes the NTP server address for clients |
| Server NTP port | 123/UDP | Standard, must not be blocked |
| Stratum | 2 (local master) or 1 if GPS-disciplined | Used by clients to qualify the source |
5.3 Configure the TP1500 Comfort as NTP client
Two parallel configuration paths are needed: the project side (TIA Portal) and the runtime side (Control Panel on the panel).
Project side (TIA Portal V16)
- Open the HMI device → Connections.
- Select the S7 connection to the S7-400.
- Confirm the connection is on the same PROFINET subnet as the CPU 416F-3 PN/DP.
- The HMI time-synchronization role of the panel is set to Slave by default when the PLC is the NTP source. Do not enable Master on the HMI side; the PLC must remain the authoritative time source.
Runtime side (Windows Embedded CE 8.0)
- Open Control Panel on the panel.
- Set Date/Time — verify the current values, then set Time Zone to the plant zone and enable Automatically adjust clock for daylight saving.
- Open Network and Dial-up Connections → select the PROFINET adapter → Internet Protocol v4 properties → tab Name Servers (or Time Server on newer CE 8.0 builds): enter the NTP server IP, check Synchronize with time server.
- Apply, then Start → Programs → Command Prompt on the panel and run
ping <NTP IP>to confirm reachability.
ping works but NTP sync does not, suspect a UDP/123 filter.6. Solution Path 2 — HMI-to-PLC Time Sync via Area Pointer
Use this when no NTP infrastructure exists at all. The PLC acts as the time master and pushes its time to the HMI every synchronization cycle.
6.1 Enable PLC-side master
- In Devices and Networks, select the HMI connection between the CPU 416F-3 PN/DP and the TP1500 Comfort.
- Open the connection properties → HMI time synchronization section.
- Select Master. This binds the S7-400 as the time authority for this HMI connection.
- Compile and download.
6.2 Confirm the HMI-side slave
- On the HMI connection, the panel role should be Slave (default when the CPU is Master).
- The HMI automatically accepts the time update and re-stamps any queued alarm events on the next refresh.
6.3 Why the "Slave" radio is sometimes greyed out
If the Slave option cannot be selected in the connection editor, the most common causes are:
- The HMI is on a different subnet than the CPU, and the connection is routed through a gateway or another CPU. Recreate the connection directly on the PROFINET subnet.
- The connection type is set to a routed S7 connection that traverses an F-proxy. PROFINET IO between the F-CPU and the HMI must be enabled, even if no I/O data is exchanged; the time sync uses the same PN channel.
- Older TIA Portal versions had the option hidden if both Master and Slave were unchecked; setting the CPU side to Master automatically fixes the panel side to Slave on the next compile.
When in doubt, fall back to Solution Path 1 (NTP). NTP does not require the Master/Slave area pointer and works across routed subnets.
7. Solution Path 3 — HMI Pushes Time to the PLC
Used only when the panel has a better time source (GPS, mobile NTP) and the PLC must follow. Set the HMI connection's HMI time synchronization to Master on the panel side. The panel writes its time into the PLC's clock every cycle. This is not appropriate for the reported installation, where multiple panels exist and the CPU is the natural time source.
8. Time Zone, UTC, and Daylight Saving Time
Comfort Panels send and receive PLC alarm timestamps in UTC. Configure both devices for one of the two consistent strategies:
| Strategy | PLC Clock Mode | HMI Time Zone | Result |
|---|---|---|---|
| Local everywhere, no DST on PLC | Local time, DST disabled | Plant zone, DST enabled | PLC alarm stamp = local time; HMI displays local time; DST handled by HMI only |
| UTC base, display local | UTC, DST disabled | Plant zone, DST enabled | PLC stamp = UTC; HMI converts to local for display; audit trail records UTC |
Pick one strategy and apply it identically to every CPU and panel in the project. Mixing strategies is the most common cause of one-hour offsets and double DST jumps.
9. Battery and Power-Cycle Behavior
The TP1500 Comfort V2 retains time across power cycles only if:
- The RTC backup battery (CR2032-style, on the back of the unit) is installed and healthy (typical life 5–10 years).
- WinCC Comfort is configured with Use time of day from the device and not Use project time (Runtime Settings → General).
If the battery is dead, the panel reverts to a default epoch (often 2008-01-01 00:00:00) on every boot. This alone will produce the exact symptom described in the case: a stale time on every screen. Replace the battery before re-architecting the time sync.
10. Verification Procedure
- From a laptop synchronized to the same NTP source, generate a PLC alarm (set a tag wired to a configured alarm at a known wall-clock time).
- On the panel, open the alarm view and confirm the timestamp matches the laptop time within ±1 s.
- Cycle power on the panel. After the next NTP sync cycle, confirm the time is restored automatically (no manual correction).
- Trigger a second alarm 5 minutes later. Confirm the new timestamp is 5 minutes after the first.
- Read the CPU 416F-3 PN/DP diagnostic buffer (online → Online & Diagnostics → Diagnostic buffer) and confirm each entry matches the panel display within ±1 s.
- Force a DST transition (or use a controlled test by changing the time zone offset) and verify the panel shifts by exactly 1 h.
11. Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| Alarm time = panel boot time after every power cycle | RTC battery dead, no sync active | Replace battery; enable NTP or PLC master sync |
| Alarm time offset by exactly N hours | Time zone mismatch between PLC and HMI | Align time zones; set both devices to UTC or both to local with consistent DST |
| Time jumps ±1 h twice a year, sometimes twice in one day | DST rules differ between devices, or DST enabled on both PLC and HMI | Disable DST on PLC; enable on HMI only |
| Slave radio button greyed out | Connection routed, or HMI on a different subnet | Recreate connection on the same PROFINET subnet; enable PROFINET IO link; or fall back to NTP |
| Panel shows "Cannot reach NTP server" | UDP/123 filtered, wrong IP, or no route | Verify ping; open UDP/123 on plant firewall; confirm PROFINET adapter has correct default gateway |
| Setting time on panel produces "Invalid value" | Out-of-range date/time entry (e.g. year 2099 with DST rules missing) | See Siemens support entry 18977107 |
| Alarm time frozen at last value | Date/Time or Coordination area pointer disabled | Re-enable the area pointer in the HMI connection |
| Different alarm times on different screens of the same panel | Each screen was historically set independently; no master ever bound | Enable NTP or PLC master; clear and re-deploy the panel image |
| CPU diagnostic buffer time correct, panel time wrong | HMI time-zone offset or DST rule wrong; or panel RTC drift | Recompute HMI time zone; enable NTP |
12. Safety Considerations on the F-CPU
The CPU 416F-3 PN/DP is a fail-safe CPU. The safety program should never derive safety actions from the wall-clock time, because a faulty time source (drift, manipulated NTP, dead RTC) is not part of the F-IE/Profisafe safety case. If a time-based safety function is genuinely required, the time source must be:
- Part of the safety integrity calculation, or
- Provided by a safety-qualified source (e.g., a hard-wired watchdog) instead of NTP.
Time stamping of safety events is fine; safety decisions on time are not.
13. Field-Proven Recommendations
- Always deploy NTP (Solution Path 1). Area pointer time sync (Path 2) is a fallback only; it is silent when the link drops, so a panel can drift for hours before anyone notices.
- If the plant has more than one HMI, all panels must point to the same NTP server. Do not let panels self-elect as master.
- Document the NTP server IP, update interval, and time zone in the project functional specification. The time configuration is part of the safety and quality case, not an afterthought.
- Schedule an annual check: confirm the panel time matches a reference clock at 12:00 local, ±2 s.
- Replace the RTC battery on a fixed schedule (every 5 years) rather than waiting for failure.
- When the panel image is upgraded from V15.1 to V16, re-test all time behavior; the regional settings DLL differs between images.
14. Frequently Asked Questions
Why do my TP1500 Comfort alarms show a different time than the S7-400 diagnostic buffer?
The PLC stamps every alarm in UTC and ships it to the HMI; the HMI converts that UTC to the configured local time zone. If the time zones differ, or the HMI has no time source, the displayed time drifts. Configure NTP on both devices or set the PLC as the HMI's time master via the HMI connection.
Can the S7-400 CPU 416F-3 PN/DP act as an NTP server for the TP1500 Comfort?
Yes. The PROFINET interface of the CPU 416F-3 PN/DP can serve NTP. The step-by-step configuration is documented in Siemens support entry ID 82203451. This is the recommended fallback when no plant NTP server is available.
The "Slave" radio button for HMI time sync is greyed out in TIA Portal V16. What should I check?
The HMI connection must be on the same PROFINET subnet as the CPU 416F-3 PN/DP, and the connection type must be a direct S7 connection (not routed through a different gateway or another CPU). Recreate the connection directly on the PN subnet, or switch to NTP synchronization (Solution Path 1) which works across routed subnets.
What is the recommended NTP update interval for an S7-400 and Comfort Panel pair?
Use 60 seconds for normal plant operation. Shorter intervals (10–30 s) increase network and CPU load without measurable accuracy gain because the S7-400 RTC is accurate to roughly ±2 s/day. For sub-second audit-trail accuracy, use a GPS-disciplined NTP server and a 10-second interval.
Do I need to upgrade the panel image from V15.01.00.02_04.01 to V16 to fix the time issue?
No. The time-sync features (NTP client, area pointer, master/slave) are available in both V15.1 and V16 images. However, Siemens support will normally ask for the image upgrade to V16 before issuing patches, so plan the upgrade during the next planned outage. Fix the time sync first using the V15.1 image, then upgrade.
What time-zone strategy should I use: UTC everywhere or local time on the PLC?
Pick one and apply it identically to every device. The simplest is local time on the PLC with DST disabled, and the same local time zone with DST enabled on the HMI. The HMI handles the DST shift, and the alarm timestamps always read in human time. The alternative — UTC on the PLC — gives a cleaner audit trail but requires operators to mentally convert UTC to local when reading the alarm view.