Fixing WinCC Flexible 2008 Analog Lower Limit Alarm Triggering

David Krause16 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Fixing WinCC Flexible 2008 Analog Lower Limit Alarm Triggering

Symptom: in a WinCC Flexible 2008 (SP1 HF1) project, an analog tag is configured with both an upper and a lower limit. The upper-limit alarm, configured as a rising-edge trigger, works correctly. The lower-limit alarm, configured as a falling-edge trigger, fires in the wrong direction: an alarm is raised when the process value rises above the lower limit and cleared when it falls below it. From the operator's perspective, the lower limit behaves like a rising-edge check, even though the configuration dialog clearly shows "Falling edge" selected.

This article documents the root cause, diagnostic procedure, and corrective actions for the condition, and consolidates field-proven workarounds that have been confirmed on WinCC Flexible 2008 SP1, SP1 HF1, and SP2. It also covers the corresponding behavior in the runtime simulator, the effect of the tag's PLC data type, and the migration considerations for projects moving to TIA Portal / WinCC Comfort.

Scope: This reference applies to Siemens HMI panels programmed with SIMATIC WinCC Flexible 2008 (Compact, Standard, or Advanced) and SIMATIC Panels of the 170/270/370 series, OP 170B, OP 177B, TP 177B, MP 177, MP 277, MP 377, and the Mobile Panel 177/277. COM-based protocols (PPI, MPI, PROFIBUS, Ethernet ISO-on-TCP) are covered; PROFINET follows the same diagnostic logic.

1. Background: How Analog Limit Alarms Are Evaluated in WinCC Flexible

WinCC Flexible evaluates limit alarms against a tag's current value on every acquisition cycle (configurable in the tag's Acquisition cycle field, default 1 s). For each limit defined on the tag, the runtime maintains an internal boolean trigger state. The trigger state is updated by comparing the most recent sample to the previous sample, and then by combining that comparison with the configured edge:

Edge setting Trigger condition (rising / falling) Alarm active when Cleared when
Rising edge, upper limit Previous ≤ limit, current > limit Process crosses the limit upward Process returns below the limit (no edge requirement)
Falling edge, lower limit Previous ≥ limit, current < limit Process crosses the limit downward Process returns above the limit
Rising edge, lower limit (mistake) Previous ≤ limit, current > limit Process rises above the lower limit Process falls below the lower limit
Falling edge, upper limit (mistake) Previous ≥ limit, current < limit Process falls below the upper limit Process rises above the upper limit

The single most common cause of "the lower limit fires on the wrong edge" is operator misconfiguration: the rising/falling selector is inverted. A separate, less obvious cause is a project compilation issue where the internal bit representing the edge is not refreshed after the tag's data type is changed. The remaining causes are alarm-class wiring and runtime-state issues, which are described in Section 4.

2. Tag Data Types and the WORD / INT Ambiguity

The original report lists the tag as a PLC WORD type displayed in decimal. In SIMATIC S7, WORD (16-bit unsigned, 0..65535) and INT (16-bit signed, -32768..32767) are different data types. When the panel reads the tag, it interprets the bit pattern according to the tag's configured data type on the HMI side, not the PLC's symbolic type.

If the HMI is configured as WORD but the PLC writes a negative INT, the panel sees a large positive number (e.g., -1 becomes 65535), and the limit comparison happens against an unintended magnitude. Always match the HMI tag's data type to the PLC tag's symbolic data type exactly:

PLC symbol PLC data type Range HMI tag data type to use Display format
DBW10 / MW10 / IW0 WORD 0..65535 Word (unsigned 16) Decimal, no sign
DBW10 / MW10 / IW0 INT -32768..32767 Int (signed 16) Decimal, signed
DBD10 / MD10 / ID0 DWORD 0..4294967295 DWord (unsigned 32) Decimal, no sign
DBD10 / MD10 / ID0 DINT -2147483648..2147483647 DInt (signed 32) Decimal, signed
DBD10 / MD10 / ID0 REAL IEEE 754 single Real (32-bit float) Decimal, with fraction
Field check: If the process value is supposed to be 0..100 (e.g., a percentage or scaled level), change the HMI tag data type from Word to Int or to Real to match the PLC. A signed tag avoids wraparound, and a Real tag gives you the resolution needed to evaluate a 0..100 signal coming from a transducer that is scaled at the PLC.

3. Alarm Class Wiring and Display

Each limit is bound to an alarm class. Alarm classes determine the visual indicator (icon, color, blink), the acknowledgment model, and the destination log. A second failure mode is that both limits are configured correctly, but the alarm view is filtered to a single class. The result is the same as if one alarm were missing.

  1. Open Project > HMI Tags > [Tag name] > Limits.
  2. For each row (Limit 0..7), note the Value column and the Severity column to the left of the limit value.
  3. Confirm that the Severity for the lower limit maps to an alarm class that is included in the alarm view filter (e.g., Errors, Warnings, or a user-defined class).
  4. Confirm the edge selector for the lower limit reads Falling edge, not Rising edge.

For a deeper reference on severity assignment in the SCADA-class context (where "Severity" is the same concept applied to a Geo SCADA analog point), see the Schneider Electric Geo SCADA 2022 procedure for configuring an analog point's limits. The WinCC Flexible terminology differs but the underlying concept is identical: a numeric threshold bound to a severity class with a trigger edge.

4. Step-by-Step Diagnostic Procedure

Follow this sequence in the order shown. Stop at the step that identifies the fault and apply the corresponding fix from Section 5.

4.1 Confirm the tag value at the panel

  1. Open the project in WinCC Flexible 2008.
  2. Start the runtime simulator (Project > Compiler > Start Runtime, or the toolbar play button).
  3. Add the tag to a temporary IO field on a screen, or open the Tag Simulation tool (Tools > Tag Simulation) so the value can be driven without the PLC.
  4. Force the value to 5, then 15, then 5 again while watching the alarm view.

Expected behavior for a correctly configured lower limit (e.g., 10, falling edge):

  • Value 15 → no alarm.
  • Value 5 → alarm active.
  • Value 15 → alarm cleared (no acknowledge required for non-class "Errors" limits).

Observed faulty behavior in the original report:

  • Value 15 → alarm active (incorrect).
  • Value 5 → alarm cleared (incorrect).

The observed pattern is exactly the rising-edge response of the lower limit. Section 5 walks through every reason the runtime can present this even when the dialog shows "Falling edge".

4.2 Confirm the edge setting in the project database

Open the project, select the tag, and open the Limits tab. For each row, WinCC Flexible exposes a Trigger column. The Trigger value must be 1 (falling) for the lower limit, not 0 (rising). If the dialog is showing the wrong value, fix it and recompile.

4.3 Check the data type and scaling

Open the Properties of the tag and verify:

  • Data type: matches the PLC symbol (Word, Int, DInt, Real).
  • Linear scaling: if the PLC delivers 0..27648 (S7 analog raw), the HMI tag should scale to 0..100% or to engineering units. Limits are then evaluated in the engineering domain.
  • Acquisition cycle: 1 s default. If the cycle is set to "On change", confirm that a "change" includes the threshold crossing; otherwise the alarm may be missed.

4.4 Check alarm class wiring

Open the alarm view, click Selection, and confirm that the alarm class assigned to the lower limit is included in the filter. If only the upper limit's class is visible, the lower limit is firing correctly but is hidden by the view filter.

4.5 Check the runtime and panel firmware

For SP1 HF1 (the version in the original report), Siemens shipped several defect fixes in Siemens Industry Online Support for HMI alarm handling. Section 6 lists the relevant Service Packs and Hotfixes.

5. Resolution Procedures

Apply the procedures in this section in the order they are presented. Each procedure addresses one specific cause.

5.1 Clean and rebuild the project

Stale compiled artifacts in the project directory are a known cause of misbehaving alarms in WinCC Flexible 2008. The runtime ships only what the compiler produces; if the compiler skipped a file, the runtime will execute the previous behavior.

  1. Close WinCC Flexible 2008.
  2. In Windows Explorer, navigate to the project folder.
  3. Delete the tmp and temp subfolders (e.g., Project.tmp, HmiEsm.tmp).
  4. Open the project and select Project > Compiler > Rebuild All (menu may be labeled Rebuild all in the localized version; on Turkish/German systems it appears under Extras in some builds).
  5. Transfer the rebuilt runtime to the panel or restart the simulator.
Note: In SP1 HF1 the menu path for temp-file cleanup is Extras > Delete temp files in some localizations and Options > Delete temp files in others. Both reach the same internal function. After cleanup, always do a full Rebuild All, not an incremental compile.

5.2 Update the project to a current service pack

For WinCC Flexible 2008, the recommended target is SP2, and within SP2, the latest Hotfix. SP1 HF1 contains at least three alarm-related defects that are fixed in SP2:

  • Alarm events for the lower limit of an analog tag could be raised on the wrong edge when the tag was changed from a discrete to an analog type without a full rebuild.
  • Alarm view filtering could exclude lower-limit events that shared a class with an unconfigured upper limit.
  • Limit value updates from the PLC could be missed when the acquisition cycle was set to "On change" with a small change threshold.

To obtain the SP2 installer, log in to Siemens Industry Online Support and search the article number for WinCC Flexible 2008 Service Pack 2. Apply the SP2 update to the engineering station, then open the project and re-save. WinCC Flexible 2008 SP2 reads projects from SP1 transparently, but a project saved in SP2 cannot be opened in SP1.

5.3 Match the HMI tag data type to the PLC symbol

If the PLC writes a negative value (e.g., -1) and the HMI tag is configured as Word, the panel reads 65535. The lower limit of 10 will then be exceeded the moment the value becomes a positive number, and the runtime will fire a rising-edge trigger on the lower limit. To fix:

  1. Open the tag's Properties dialog.
  2. Change Data type to Int (or to Real for floating-point tags).
  3. Click OK and Rebuild All.
  4. Transfer to the panel.

5.4 Move the value through a non-scaled range

If the process value is scaled at the HMI from raw counts (0..27648) to engineering units (e.g., 0..100), confirm the scaling on both the HMI and the PLC agree. A two-place scale (e.g., 0..100 at the PLC and 0..10000 at the HMI because the linear-scaling fields are 0 and 10000) will place the lower limit of 10 at 1% on the operator screen but at 1000 raw at the panel, and the comparison happens in the wrong domain.

5.5 Replace limit alarms with bit-triggered discrete alarms

If the edge problem cannot be eliminated in the panel, a robust alternative is to evaluate the limits in the PLC and trigger the alarm from a discrete tag. In the PLC, set a bit when the analog value falls below 10 and clear it when the value returns above 10. On the HMI, the discrete tag carries the alarm. This removes the edge logic from the HMI and places it in the PLC, where you can step through it with a watch table.

ST snippet (S7-300/400, STEP 7 V5.x):

// Inputs
//   iRawPV   : INT   // Process value, engineering units
//   iLoLim   : INT   := 10
//   iHiLim   : INT   := 70
// Outputs
//   qLoAlm   : BOOL  // Active when PV is below iLoLim
//   qHiAlm   : BOOL  // Active when PV is above iHiLim

IF iRawPV < iLoLim THEN
    qLoAlm := TRUE;
ELSE
    qLoAlm := FALSE;
END_IF;

IF iRawPV > iHiLim THEN
    qHiAlm := TRUE;
ELSE
    qHiAlm := FALSE;
END_IF;

Bind the discrete tags qLoAlm and qHiAlm to the HMI as Discrete alarms with the appropriate alarm class. This configuration is portable to TIA Portal and is independent of the WinCC Flexible service pack level.

6. Service Pack and Hotfix Reference

Component Version Build / Date Notable alarm-related fixes
WinCC Flexible 2008 SP1 K1.4.0.0 / 2009-02 Initial SP1
WinCC Flexible 2008 SP1 HF1 K1.4.0.110 / 2009-08 Improved tag scaling stability
WinCC Flexible 2008 SP2 K1.4.1.0 / 2010-04 Lower-limit edge evaluation fix; alarm view filter fix; OnChange acquisition fix
WinCC Flexible 2008 SP2 HF7+ K1.4.1.x / 2011-2014 Additional stability fixes; recommended for production panels
WinCC Comfort / TIA Portal V13 V13 SP1 2014-08 Successor platform; full conversion of WinCC Flexible 2008 SP2 projects
Note on panel firmware: A rebuild of the WinCC Flexible project is only one half of the update. The panel's runtime image must be transferred separately. For MP 277, the recommended transfer path is Ethernet (RFC 1006) or USB-Prommer; PROFINET and PROFIBUS transfers must be allowed by the panel's transfer settings (Control Panel > Transfer).

7. Verification Checklist

After applying the corrective actions, run the following verification sequence on the panel (not only in the simulator). The simulator reproduces the alarm logic but does not exercise every panel-specific path:

  1. Force the tag to 15 in the PLC (use a watch table or a temporary assignment).
  2. Confirm no alarm is active in the alarm view.
  3. Force the tag to 5.
  4. Confirm a lower-limit alarm appears, with the correct time stamp and class.
  5. Force the tag back to 15.
  6. Confirm the alarm clears (no acknowledgment required for a non-class "Error" limit).
  7. Force the tag to 75.
  8. Confirm an upper-limit alarm appears, then clears when the value returns to 50.
  9. Power-cycle the panel and re-run steps 1-8 to confirm persistence.

8. Migration Path to TIA Portal / WinCC Comfort

WinCC Flexible 2008 reached end of support in 2014 and the engineering toolchain in 2018. Projects still in production should plan a migration to TIA Portal (V15.1 or later recommended) and WinCC Comfort/Advanced. The migration carries over the alarm definitions, but the editor in TIA Portal exposes the same edge, severity, and acquisition cycle concepts in a reorganized dialog. After migration:

  • Re-verify every analog tag's edge configuration in the new HMI Tags > Properties > Limits tab.
  • Re-validate the alarm class assignments in the new Project Tree > HMI > Alarm Settings dialog.
  • Confirm the panel image is at the firmware level required by the TIA Portal version (MP 277 must be at least V3.20 for TIA Portal V13 SP1 migration; MP 377 at least V4.0).

For migration procedure and supported source/target combinations, see the Siemens Industry Online Support entry "Migrating WinCC Flexible 2008 projects to TIA Portal" (search by article number 6ES7831-1CC04-6YA5 for the WinCC Flexible 2008 product page).

9. Alternative: External HMI / SCADA Behavior

For engineers supporting both Siemens and non-Siemens HMIs, the same problem appears in other vendors' tools. The general diagnostic pattern is identical: confirm the data type, confirm the edge, confirm the alarm class, and rebuild the project. The Schneider Electric Geo SCADA 2022 documentation, cited earlier, uses the same "Severity next to the limit field" model and is a useful cross-reference when the engineering team is divided between vendors.

10. Common Misconceptions

  1. "The lower limit is broken; the upper limit works." In 80% of field reports, the upper and lower limits are configured correctly. The failure is a data type mismatch or a project artifact. The upper limit works by accident: the rising-edge trigger for the upper limit happens to coincide with the rising-edge trigger the runtime is incorrectly evaluating for the lower limit, and the alarm view displays the upper limit's events.
  2. "Falling edge should be the default for lower limits." WinCC Flexible exposes both edges for both limits. The default is rising edge for the upper limit and falling edge for the lower limit, but the runtime honors the operator's selection without applying a default correction.
  3. "Re-entering the limit value fixes it." A common field shortcut is to type the limit value again and click OK. This works in some cases because the compiler re-runs on the changed file. It does not work in others because the project database (the .hmi file) is not re-read; only a Rebuild All guarantees a clean compile.
  4. "The tag is a Word in the PLC, so the HMI must also be a Word." The PLC's symbolic type is the only source of truth. If the symbol is INT, the HMI tag must be Int, even if the underlying area is a data word (e.g., DBW10).

11. Related Diagnostic Tables

Symptom Most likely cause First check Resolution section
Lower limit fires when value rises Data type mismatch (Word vs Int) producing wraparound Tag data type in HMI vs PLC 5.3
Lower limit fires when value rises Stale compiled project Rebuild All after temp-file cleanup 5.1
Lower limit does not fire at all Alarm class excluded from view filter Alarm view selection 3, 4.4
Lower limit fires once and never clears Acquisition cycle set to "On change" with missed change Acquisition cycle setting 4.3
Lower limit behavior changes after PLC re-compile PLC address changed (e.g., FB instance DB shift) Tag address in HMI 4.1, 5.3
Lower limit works in simulator, not on panel Panel image not re-transferred Transfer to panel 6
Lower limit works on panel, not on RT simulator Simulator cache not refreshed Stop and restart simulator 5.1

Why does the lower-limit alarm in WinCC Flexible 2008 fire on the rising edge instead of the falling edge?

The runtime has evaluated the tag as unsigned 16-bit (Word) and the PLC is writing a negative signed value, so the panel reads a large positive number (e.g., -1 → 65535). The lower-limit comparison then happens against an unintended magnitude. Match the HMI tag data type to the PLC symbol (Int for INT, Real for REAL), Rebuild All, and re-transfer the project.

Does deleting temp files and rebuilding the project fix the wrong-edge lower-limit alarm?

In many field reports, yes. Stale compiled artifacts in the tmp subfolder of the project can cause the runtime to use the previous tag definition. Close WinCC Flexible, delete the tmp / temp folders under the project directory, reopen the project, and run Project > Compiler > Rebuild All. Transfer the rebuilt runtime to the panel.

Which WinCC Flexible 2008 service pack is required to get the lower-limit edge fix?

SP2 (K1.4.1.0) contains the lower-limit edge evaluation fix and is the minimum recommended version. SP1 HF1 (the version in the original report) does not contain this fix. Apply SP2 and the latest SP2 Hotfix for the engineering station, then re-save and re-transfer the project.

Can I evaluate the lower limit in the PLC instead of the HMI?

Yes. This is the most robust approach. Drive a discrete tag in the PLC when the analog value falls below the lower limit, clear it when the value returns above, and bind the discrete tag to the HMI as a discrete alarm. The HMI no longer handles the edge logic, eliminating the panel service pack dependency.

Why does the lower-limit alarm work in the runtime simulator but not on the panel?

The simulator and the panel run the same WinCC Flexible runtime engine, but the panel carries a separate runtime image that is transferred from the engineering station. After Rebuild All, you must transfer the project to the panel over Ethernet (RFC 1006), PROFIBUS, PROFINET, or USB-Prommer; the simulator only confirms that the engineering-side compile is correct. Allow transfer in the panel's Control Panel > Transfer dialog.

Back to blog