Logging MP377 Tags to SQL Database via WinCC Flexible Runtime

David Krause12 min read
HMI / SCADASiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview of MP377 SQL Logging Challenge

The SIMATIC MP377 19-inch color HMI (part numbers 6AV6644-2AD01-2AX1 for touch, 6AV6644-2AE01-2AX1 for key variants) runs Microsoft Windows CE 6.0 and executes WinCC Flexible Runtime as its visualization engine. Operators and engineers commonly need to log process tags to a SQL database for historian, reporting, or MES integration, but the MP377 platform does not support direct ODBC/SQL data logging out of the box. This reference documents the four production-proven methods to achieve SQL logging from an MP377: (1) CSV file logging with remote PC synchronization, (2) OPC DA server bridging, (3) script-driven file transfer with Windows-side ingestion, and (4) migration to a WinCC Advanced/Comfort runtime on a PC-based or later multi-panel platform.

Platform constraint: Windows CE 6.0 lacks the ODBC driver stack, .NET Framework 4.x, and SQL Server Native Client required for inline SQL INSERT statements. Any solution must either (a) keep the MP377 writing local files and post-process them on a Windows host, or (b) push tag values to a Windows service that owns the database connection.

2. MP377 Hardware and Software Platform

Attribute Specification
Display 19-inch TFT, 1280 x 1024 pixels, 16M colors
Processor Intel Celeron M 1.0 GHz
RAM / Storage 512 MB DDR2 / 2 GB CFast or 1 GB flash
Operating System Windows CE 6.0 (multi-language MUI)
Runtime Software WinCC Flexible Runtime 2008 SP5 (last supported)
Configuration Tool SIMATIC WinCC Flexible 2008 SP5 (ES)
Interfaces 2 x PROFINET, 2 x USB 1.1, RS422/485, CFast slot
OPC Support OPC DA Server 2.05a (built-in runtime option)
Max Power Tags 4096 (with PowerTag option)
Supported SQL Backends None natively; ODBC stack absent

For the official product manual and firmware compatibility matrix, see the Siemens MP377 Operating Instructions and the WinCC Flexible 2008 SP5 Readme.

3. WinCC Flexible Runtime Logging Architecture

WinCC Flexible Runtime exposes three logging primitives that execute inside the HMI device:

  1. Tag Logging — cyclic or event-driven capture of internal and external tags into a circular buffer.
  2. Alarm Logging — discrete event recording with timestamp, state, and acknowledgement.
  3. Audit Trail — operator action logging for FDA 21 CFR Part 11 compliance scenarios.

All three are persisted to the local storage medium (CFast card, USB stick, or internal flash) in one of two formats:

  • RDB format — proprietary segmented binary database, viewable only via the WinCC Flexible ES or the add-on WinCC Flexible ES Archive Viewer.
  • CSV (TXT/CSV) export — comma-separated, line-oriented text, one record per row, written through the integrated export function or a user-defined VBScript.

The WinCC Flexible 2008 help system (F1 in the ES) documents the LogTag, LogTagArchive, and ExportTags VBScript objects that can be called from a scheduled task. The Microsoft VBScript reference defines the available language subset; note that WinCE supports only VBScript 5.x without late binding to ADODB.

4. Why Direct SQL Logging is Not Supported on MP377

The MP377 runtime is built on Windows CE 6.0, which omits several desktop-Windows components required for transparent SQL connectivity:

  • No Microsoft ODBC Driver Manager (sqlsrv32.dll equivalent is absent).
  • No SQL Server Native Client (sqlncli.dll) and no OLE DB provider for SQL Server.
  • No System.Data.SqlClient in the .NET Compact Framework 3.5.
  • No TCP/IP socket libraries exposing the TDS protocol to VBScript.
Workaround distinction: WinCC Advanced (TIA Portal V11 and later) running on a Windows PC panel or Win 7/10 IPC can write directly to SQL Server via the Database Logger option, but the MP377 with WinCE cannot load this runtime. Any solution must therefore respect the platform boundary.

5. Method 1: CSV File Logging on MP377 with Remote PC Sync

This is the simplest and most reliable approach when the MP377 and the SQL host reside on the same LAN. The HMI writes a comma-separated file to a shared network folder; a Windows service on the SQL host tail-inserts the rows.

5.1 Configure CSV Export in WinCC Flexible

  1. Open the WinCC Flexible ES project and select Logs → Tag Log.
  2. Create a new log (e.g., ProcessLog_1s) with a 1-second acquisition cycle.
  3. Add the required tags to the log columns (e.g., Pressure_PV, Temperature_PV, Flow_PV).
  4. In the Properties of the tag log, switch the Storage Location from RDB to CSV (Export) and define a path such as \SQL-HOST\HMI_Logs\MP377_01\.
  5. Set the Segment Size to 1000 records and enable Overwrite oldest segment for non-stop operation.

5.2 Share a Folder on the SQL Host

  1. Create C:\HMI_Logs\MP377_01 on the SQL host.
  2. Right-click → Properties → Sharing → Advanced Sharing.
  3. Share as HMI_Logs$ (hidden share) and grant Everyone : Change.
  4. Set NTFS permissions to allow Authenticated Users : Modify.

5.3 SMB/CIFS Compatibility with Windows CE 6.0

Windows CE 6.0 supports SMB 1.0 and SMB 2.0 (with the WinCE 6.0 R3 QFE package). The shared folder must be reachable by UNC path from the MP377. Configure the HMI's network adapter:

  • IP address (e.g., 192.168.10.50/24)
  • Default gateway and DNS if the SQL host is on a different subnet.
  • WINS server optional; for direct \\SQL-HOST\HMI_Logs$ path, WINS is recommended.

Microsoft's SMB protocol reference documents the supported dialects.

5.4 SQL Host Ingestion Service

On the SQL Server machine, deploy a small .NET Framework 4.8 console application or Windows Service that watches the directory and bulk-inserts new CSV rows. Sample C# skeleton:

using System.IO;
using System.Data.SqlClient;

class HmiCsvIngester
{
    static void Main()
    {
        var watcher = new FileSystemWatcher(@"C:\HMI_Logs\MP377_01", "*.csv");
        watcher.Created += OnCsvCreated;
        watcher.EnableRaisingEvents = true;
        System.Threading.Thread.Sleep(-1);
    }

    static void OnCsvCreated(object s, FileSystemEventArgs e)
    {
        using (var bulk = new SqlBulkCopy(@"Server=.;Database=ProcessHistorian;Integrated Security=true;"))
        {
            bulk.DestinationTableName = "dbo.HMI_ProcessLog";
            bulk.ColumnMappings.Add("Timestamp", "LogTime");
            bulk.ColumnMappings.Add("TagName", "TagName");
            bulk.ColumnMappings.Add("Value", "TagValue");
            using (var reader = new StreamReader(e.FullPath))
                bulk.WriteToServer(new CsvDataReader(reader));
        }
    }
}

The destination table schema is shown in Section 9.

6. Method 2: OPC DA Server Bridging

The MP377 with WinCC Flexible Runtime can publish its internal tags as an OPC DA 2.05a server (option OPC Server in the runtime license). A Windows service can subscribe to those tags via the OPC Foundation .NET API and INSERT each value into SQL Server in real time.

6.1 Enable OPC DA on MP377

  1. Install the WinCC Flexible Runtime OPC Server option (separate license, part of the WinCC Flexible/ES Options package).
  2. Configure the OPC server via the WinCC Flexible OPC Configurator on a Windows ES PC; export the tag namespace to the MP377.
  3. On the MP377 control panel, launch the OPC Configurator and set the server's listen port (default 135) and DCOM authentication. Use the machine's local user account rather than domain credentials to avoid Kerberos dependencies on WinCE.

6.2 OPC-to-SQL Bridge on Windows

Microsoft's SqlBulkCopy and the OPC Foundation's OPC DA .NET wrapper enable a high-throughput bridge. The bridge should run as a Windows service and maintain one subscription per MP377 with the requested update rate (typically 100 ms to 1 s).

6.3 Network and DCOM Configuration

  • Open inbound TCP 135 plus the dynamic RPC range (49152–65535) on the MP377 Windows Firewall if the runtime is hardened.
  • Disable DCOM callback authentication on the bridge host (dcomcnfg.exe → Default Properties → Enable Distributed COM unchecked when the LAN is trusted).
  • Verify connectivity with opcda2.exe -host MP377-01 from the OPC Quick Client.
Reliability caveat: OPC DA over DCOM is sensitive to network jitter. For new deployments consider the OPC UA migration path described in Section 8, or evaluate a third-party native OPC UA server for WinCE such as Unified Automation UA Server for WinCE.

7. Method 3: Script-Driven File Generation and FTP Push

For networks that prohibit SMB shares, WinCC Flexible scripts can generate CSV files and push them via FTP/HTTPS to the SQL host.

7.1 VBScript to Write a CSV Row

Function WriteLogRow(filePath, tagName, value)
    Dim fso, ts
    Set fso = CreateObject("Scripting.FileSystemObject")
    Set ts = fso.OpenTextFile(filePath, 8, True) ' ForAppending
    ts.WriteLine Now & "," & tagName & "," & value
    ts.Close
End Function

7.2 Scheduled Task

  1. In WinCC Flexible ES, open Schedules and create a 1-second trigger named Log_Tick_1s.
  2. Add a Run Script function calling WriteLogRow for each tag.
  3. Insert a daily job at 00:00:05 that calls a PowerShell-equivalent FTP push via a WinCE console utility such as curl.exe (provided by the WinCE Console Tools add-on).

7.3 FTP Server on the SQL Host

Use IIS FTP with the IIS 8.5 FTP role or a lightweight alternative such as FileZilla Server. The SQL ingestion service watches the inbound directory and bulk-loads each closed file.

8. Method 4: Migration to WinCC Advanced / TIA Portal

If the SQL logging requirement is non-negotiable and the plant is undergoing a refresh, migrate the visualization to a TIA Portal-based runtime. WinCC Advanced V11 and later include the Database Logger option that writes directly to MS SQL Server 2012 or higher without intermediary scripts.

8.1 Target Platforms

Target Runtime SQL Logger Support
Comfort Panel TP1500 / TP1900 WinCC Comfort V17 Yes (via Database Logger option)
IPC477E / IPC677D WinCC Runtime Advanced V17 Yes
Win 10 IoT IPC with TIA V17 WinCC Runtime Advanced V17 Yes
MP377 (existing) WinCC Flexible 2008 SP5 No

8.2 Database Logger Configuration

  1. Insert a Database Logger object in the TIA Portal project tree.
  2. Define the connection string: Data Source=SQL-HOST;Initial Catalog=ProcessHistorian;Integrated Security=SSPI;
  3. Map tags to columns in the destination table.
  4. Compile and download. The runtime inserts rows via a buffered TDS connection.

See the WinCC Runtime Advanced V17 Database Logger manual for the full reference.

9. SQL Database Schema for Imported Tags

Regardless of which ingestion method is chosen, the destination table should use a normalized schema with a clustered index on the timestamp column.

CREATE TABLE dbo.HMI_ProcessLog (
    LogId       BIGINT IDENTITY(1,1) NOT NULL,
    LogTime     DATETIME2(3) NOT NULL,
    TagName     NVARCHAR(64) NOT NULL,
    TagValue    NVARCHAR(128) NULL,
    Quality     TINYINT NOT NULL,
    SourceHMI   NVARCHAR(32) NOT NULL,
    CONSTRAINT PK_HMI_ProcessLog PRIMARY KEY CLUSTERED (LogTime, SourceHMI, TagName)
);

CREATE NONCLUSTERED INDEX IX_HMI_ProcessLog_TagName
    ON dbo.HMI_ProcessLog (TagName, LogTime DESC);

The Quality column maps the OPC quality byte (0=Bad, 1=Uncertain, 0xC0=Good) so analysts can filter transient communication drops.

10. Network Configuration Matrix

Method Ports Used Firewall Rules Required Latency Tolerance
CSV over SMB TCP 445, 139 Open SMB on SQL host File loss risk on disconnect; resilient to short blips
OPC DA TCP 135 + dynamic 49152–65535 DCOM endpoints Sub-second; sensitive to jitter
FTP push TCP 21 (or 990 for FTPS) FTP listener Batched; tolerant of intermittent links
Database Logger (TIA V17) TCP 1433 SQL Browser if named instance Sub-second with buffered insert

11. Verification and Acceptance Test

  1. Network reachability — From the MP377, Ping SQL-HOST returns < 5 ms on the LAN. Verify with the WinCE Network Diagnostics control panel applet.
  2. Write test — Trigger a tag change in WinCC Flexible and confirm a new row appears in dbo.HMI_ProcessLog within two acquisition cycles.
  3. Load test — Force 200 tags at 1 s cycle for 1 hour; confirm 720,000 rows landed and the ingestion service CPU stays below 25 %.
  4. Disconnect drill — Disconnect the LAN cable for 60 s. CSV method must buffer locally and resync; OPC method must reconnect within 30 s and mark missing samples as Quality=Bad.
  5. Failover — Stop the SQL ingestion service for 5 min, restart, and confirm the service resumes from the last unprocessed CSV segment.

12. Troubleshooting Matrix

Symptom Likely Cause Resolution
CSV file not created on share SMB authentication failure; CE user lacks write rights Verify share permissions and credentials in MP377 control panel; check Windows CE Security Configuration Tool
OPC client cannot browse MP377 tags DCOM authentication mismatch; firewall blocking Set Default Authentication Level = None on the bridge host; open RPC ports
Rows missing in SQL after a network blip CSV segment rotated during disconnect; ingestion service missed notification Implement directory rescan every 5 min as a catch-up
Time drift between HMI and SQL MP377 RTC not synchronized; WinCE lacks time-zone-aware DST handling Configure SNTP server on the HMI control panel pointing to the domain controller; see Windows Time Service
Database Logger option missing in TIA V17 License not installed Order 6AV6371-1DQ17-0AX0 for Runtime Advanced; transfer license via Automation License Manager
VBScript CreateObject("ADODB.Connection") fails on MP377 ADODB not present on WinCE 6.0 Switch to file-based export; ADODB is unsupported on WinCE 6.0 per Microsoft documentation

13. Field-Commissioning Checklist

  • [ ] MP377 firmware verified against WinCC Flexible 2008 SP5 ES compatibility list (see Siemens KB entry 44391048).
  • [ ] Network share or OPC server reachable from HMI ping test.
  • [ ] Service account for the ingestion service has db_datawriter on ProcessHistorian.
  • [ ] Backup of RDB archives on MP377 CFast card taken before switching to CSV mode.
  • [ ] Time zone of MP377 set to plant standard; SNTP server address configured.
  • [ ] Audit trail of configuration change recorded in the plant change log.

14. Safety and Operational Notes

Tag logging is a non-critical process; loss of historical data must not affect control. The MP377 must continue to run the visualization and operator input handling even when the network path to the SQL host is unavailable. Confirm that the chosen method buffers locally and that the local storage is sized for at least 48 hours of worst-case logging at full tag density. For an MP377 with 2 GB CFast and 200 tags at 1 s cycle, a CSV file with 17.2 million rows consumes approximately 1.4 GB, so configure segment rotation at 1 million rows or daily, whichever comes first.

15. FAQ

Can WinCC Flexible Runtime on MP377 write directly to SQL Server?

No. Windows CE 6.0 on the MP377 lacks the ODBC driver stack and .NET SqlClient required for direct INSERT statements. Use the CSV, OPC, or FTP bridging methods described in Sections 5–7, or migrate to a TIA Portal V17 platform with the Database Logger option.

What is the recommended minimum WinCC Flexible version for MP377 SQL bridging?

WinCC Flexible 2008 SP5 is the last service pack supporting the MP377. Use this version on the ES side and pair it with the matching runtime image downloaded to the HMI to avoid tag-namespace inconsistencies.

How do I share a folder on the SQL host that the MP377 can write to?

Create a hidden share such as HMI_Logs$ with Change permissions for the Authenticated Users group, and reference it from the MP377 as \\SQL-HOST\HMI_Logs$\MP377_01\ in the WinCC Flexible CSV export path. Ensure TCP 445 is open on the SQL host firewall.

Does OPC DA survive a 60-second network outage?

The OPC DA subscription reconnects automatically after the DCOM service re-establishes the call. During the outage the bridge will record OPC_QUALITY_BAD for affected tags; backlog cannot be filled retroactively, so combine the OPC method with a CSV safety log if no data loss is acceptable.

What is the simplest path to native SQL logging without replacing the HMI hardware?

Run a Windows service (e.g., a .NET 4.8 console host) on a plant-floor PC that pulls tags from the MP377 via OPC DA and writes to SQL Server with SqlBulkCopy. This adds no load to the MP377 beyond its existing OPC server and requires only that the PC be on the same VLAN.

Back to blog