Overview
Siemens LOGO! 0BA7 (and later 0BA8 / 0BA9) Base Modules expose a subset of internal parameters to the Variable Memory (VM) area so that HMIs, SCADA systems, and PLC peer-to-peer connections can read and write them. When commissioning a LOGO! 0BA7 with WinCC flexible, WinCC (TIA Portal), or WinCC Unified, the engineering task of mapping a Weekly Timer block (function block B04) is one of the most error-prone procedures because the timer stores its on-time, off-time, and day-of-week mask in a BCD-coded Word rather than a binary integer. This reference documents the exact memory layout, the VM mapping dialog workflow, the supported WinCC tag data types, and the bit-level conversion required to view and write the timer values from the HMI.
Prerequisites
- LOGO! Base Module with order number 6ED1052-xxx08-0BA0 (0BA8) or 6ED1052-1MD08-0BA0 (0BA7) or later. The 0BA7 family includes the LOGO! 12/24 RCE, LOGO! 24, LOGO! 230 RCE and the pure variants.
- LOGO!Soft Comfort V8.x or later installed. VM parameter mapping is exposed under Tools → Parameter VM Mapping and is only available when the target device is 0BA7 or newer.
- WinCC flexible 2008 SP5 or WinCC (TIA Portal) V13 SP1+ with the LOGO! driver. WinCC Unified V16+ supports LOGO! 0BA8/0BA9 via the SIMATIC LOGO! RT Unified channel; V17/V18 add the V8.4 protocol extensions.
- An Ethernet connection between the LOGO! Base Module and the HMI / PC. For 0BA7, the on-board RJ45 port exposes a 10/100 Mbit interface; the LOGO! CSM module can be added if more ports are required.
- One configured Weekly Timer (function block B04) inside the LOGO! circuit program.
LOGO! 0BA7 VM Mapping Architecture
The Variable Memory of a LOGO! 0BA7 Base Module is 850 bytes wide by default. The first 64 bytes are reserved for digital and analog I/O, network I/O (NAI0..NAI7, NAQ0..NAQ7), and the fixed bit-mapped markers. The remainder of the VM area contains the parameter buffer, which holds a copy of the current value of every parameterized function block output (timers, counters, analog thresholds, PI controllers, etc.).
Through the Parameter VM Mapping dialog (see Siemens Knowledge Base entry 100782807), the engineer can move up to 64 parameters out of the parameter buffer into a deterministic, ascending VM address range. Only parameters that are explicitly mapped this way can be addressed symbolically from WinCC. The dialog enumerates the block number, block parameter name, and the underlying data format of each value. The DataFormat column is the source of truth for selecting the correct WinCC tag type.
VM address layout for mapped parameters
LOGO!Soft Comfort allocates mapped parameters in the variable memory region starting at byte 0 and growing upward. Each entry consumes the byte footprint of its data type:
| Data type | Length | VM footprint | Typical LOGO! parameter |
|---|---|---|---|
| Bool | 1 bit | 1 bit | Block enable, day-of-week bits |
| Byte | 1 byte | 1 byte | Time base (seconds, minutes, hours), weekday mask index |
| Word | 2 bytes | 2 bytes | On-time, Off-time, Threshold |
| Int | 2 bytes (signed) | 2 bytes | Counter actual value, analog thresholds |
| DInt | 4 bytes (signed) | 4 bytes | PI controller setpoint/output, runtime counter |
| Real | 4 bytes (float, IEEE-754) | 4 bytes | Analog flag, max/min value, math result |
The address reported in the VM mapping dialog is the absolute byte offset into the VM area. For example, an On-time mapped to VM word address 850 will be read by the HMI as VM word 850 (little-endian byte order).
Weekly Timer Block Memory Layout
The Weekly Timer function block (B04) takes seven Boolean inputs (one per weekday: Mo, Tu, We, Th, Fr, Sa, Su) and exposes three parameters that can be mapped to VM:
| Parameter | DataFormat (per VM Mapping) | Encoding | Range |
|---|---|---|---|
| Time base | Byte (value 1, 2, or 3) | Selection: 1 = seconds, 2 = minutes, 3 = hours | 1..3 |
| On-time | Word (BCD-coded) | HH:MM packed in BCD, 16-bit | 00:00..23:59 |
| Off-time | Word (BCD-coded) | HH:MM packed in BCD, 16-bit | 00:00..23:59 |
The On-time word uses the following bit layout (byte-wise little-endian on the VM, low byte first):
- Bits 0–3: Minutes ones digit (BCD 0..9)
- Bits 4–6: Minutes tens digit (BCD 0..5)
- Bit 7: Minutes unused / constant 0
- Bits 8–11: Hours ones digit (BCD 0..9)
- Bits 12–14: Hours tens digit (BCD 0..2)
- Bit 15: Hours unused / constant 0
For example, the time 14:35 is stored as 0x1435 in the On-time word. Writing a value of 0x09 05 corresponds to 09:05; 0x00 00 corresponds to midnight.
Step-by-Step: Mapping Weekly Timer Parameters in LOGO!Soft Comfort
- Open the circuit program in LOGO!Soft Comfort and locate the Weekly Timer block. Right-click the block and select Block Properties → confirm the block number (for example, B04, instance 1).
- On the menu bar choose Tools → Parameter VM Mapping. The Variable Memory Configuration dialog opens.
- Click Add. A row appears containing the block number, parameter, and the data format read from the LOGO! kernel.
- Set the Parameter filter to Weekly Timer, expand the block instance, and select the three parameters TimeBase, OnTime, and OffTime.
- Verify the DataFormat column shows Byte for TimeBase and Word for OnTime / OffTime. If a parameter reads Unknown, the LOGO! target device setting in the project properties is older than 0BA7 — change it under File → Properties → Target Device.
- Click OK to write the mapping into the circuit program. Transfer the program to the LOGO! Base Module via Ethernet or SD card.
- Note the resulting VM addresses shown in the dialog. These will be used as the Address field of the WinCC tags.
Configuring WinCC Tags for the Weekly Timer
For each mapped parameter, create a WinCC tag with the following properties. The table below assumes VM addresses 850 (TimeBase), 851 (OnTime), 853 (OffTime) for illustration purposes; the real addresses are issued by the VM mapping dialog.
| WinCC tag name | VM address | Data type | Length | Acquisition | Display purpose |
|---|---|---|---|---|---|
WT1_TimeBase |
VW 850 | Byte | 1 byte | Cyclic 1 s | Drop-down: 1=s, 2=min, 3=h |
WT1_OnTime |
VW 851 | Word | 2 bytes | Cyclic 1 s | Time-of-day I/O field (BCD decoded) |
WT1_OffTime |
VW 853 | Word | 2 bytes | Cyclic 1 s | Time-of-day I/O field (BCD decoded) |
WT1_Mo .. WT1_Su
|
VB 855, bit 0..6 | Bool | 1 bit each | Cyclic 1 s | Day-of-week checkboxes |
For WinCC (TIA Portal) the configuration is done in the HMI tag table: address DB1,DBW850 (or raw VW850), type Word. For WinCC Unified RT, the same address is configured under HMI tags → SIMATIC LOGO! connection with the data types Bool / Byte / Int / DInt / Word as documented at TIA Portal Help: Permitted data types for SIMATIC LOGO! RT Unified.
Decoding BCD Time Values for HMI Display
To display the On-time / Off-time Word as a human-readable HH:MM string on the HMI, apply a BCD-to-binary conversion. The expression below is given in Structured Text and can be bound to a property or a separate calculated tag in WinCC Unified.
// Decode LOGO! BCD time word into integer hour and minute
FUNCTION_BLOCK LOGO_TimeDecode
VAR_INPUT
bcdWord : WORD;
END_VAR
VAR_OUTPUT
nHour : INT;
nMinute : INT;
bError : BOOL;
END_VAR
VAR
lowNibble : BYTE;
highNibble : BYTE;
END_VAR
lowNibble := WORD_TO_BYTE(bcdWord AND 16#000F); // minutes ones
highNibble := WORD_TO_BYTE((bcdWord AND 16#00F0) / 16#10); // minutes tens
nMinute := WORD_TO_INT(highNibble) * 10 + WORD_TO_INT(lowNibble);
lowNibble := WORD_TO_BYTE((bcdWord AND 16#0F00) / 16#100); // hours ones
highNibble := WORD_TO_BYTE((bcdWord AND 16#F000) / 16#1000); // hours tens
nHour := WORD_TO_INT(highNibble) * 10 + WORD_TO_INT(lowNibble);
bError := (nHour > 23) OR (nMinute > 59);
END_FUNCTION_BLOCK
For WinCC flexible 2008 (no ST support), use the same logic with the Calculation field on a numeric I/O field:
// WinCC flexible — expression on the I/O field 'OnTime_Hour'
((DWORD_TO_INT(('WT1_OnTime' AND 0xF000) / 0x1000)) * 10)
+ DWORD_TO_INT(('WT1_OnTime' AND 0x0F00) / 0x100)
Bind the result to a numeric I/O field with format zz (two digits, zero-padded) and a limit range of 0..23.
Writing Time Values from the HMI Back to LOGO!
The reverse direction is symmetric: the HMI user enters hours and minutes, the script recombines them into a BCD word, and writes the value to the VM address. Use a C script in WinCC flexible or a tag procedure in WinCC Unified:
// WinCC flexible C script — On the 'WriteTime' button
{
int hour = GetTagWord("WT1_OnTime_Hour");
int minute = GetTagWord("WT1_OnTime_Minute");
DWORD bcdTime = 0;
// pack tens & ones of hour into nibble 3 & 2
bcdTime = ((hour / 10) << 12) & 0xF000;
bcdTime |= ((hour % 10) << 8) & 0x0F00;
// pack tens & ones of minute into nibble 1 & 0
bcdTime |= ((minute / 10) << 4) & 0x00F0;
bcdTime |= (minute % 10) & 0x000F;
SetTagWord("WT1_OnTime", (WORD)bcdTime);
}
Displaying and Editing the Day-of-Week Mask
The day-of-week selection is stored as a one-byte bitmask (bit 0 = Monday ... bit 6 = Sunday). In WinCC create seven separate Bool tags, each pointing to one bit of the byte at the address reported in the VM mapping dialog:
-
WT1_Mo→ DB1.DBX855.0 -
WT1_Tu→ DB1.DBX855.1 -
WT1_We→ DB1.DBX855.2 -
WT1_Th→ DB1.DBX855.3 -
WT1_Fr→ DB1.DBX855.4 -
WT1_Sa→ DB1.DBX855.5 -
WT1_Su→ DB1.DBX855.6
Bit 7 of the day-of-week byte is reserved. Configuring a tag of type Word on the same address and masking 0x7F yields a value directly usable in drop-down lists for an aggregated view.
Verification
- In LOGO!Soft Comfort, open Tools → Parameter VM Mapping and confirm three rows exist for the Weekly Timer with addresses that increase by 2 between OnTime and OffTime (each is a Word).
- Start the WinCC runtime and the LOGO! simulation. The on-screen time field should read 00:00 for an unconfigured timer.
- Write a known time, for example 14:35, using the HMI. Watch the Output LED of the Weekly Timer block in LOGO!Soft Comfort online mode. Force a real-time clock advance past 14:35:00 and verify the output transitions high at the right second.
- Toggle each day-of-week checkbox. In the LOGO!Soft Comfort mask view, the corresponding weekday input (Mo..Su) of the Weekly Timer block should update within one acquisition cycle (1 s by default).
- Stop and restart the LOGO! without cycling power. Verify the timer parameters retain their last written values. If they reset, the mapping is not being saved to the LOGO! non-volatile store — transfer the program to the LOGO! again with PC → LOGO!, ensuring the option Parameter VM Mapping is included in the transfer set.
Troubleshooting Matrix
| Symptom | Likely root cause | Remediation |
|---|---|---|
| WinCC tag shows quality Bad | VM address outside the mapped range or HMI driver set to wrong LOGO! type | Re-run Tools → Parameter VM Mapping; confirm the address exists in the dialog; in WinCC select driver SIMATIC LOGO!, not S7-200 |
| Time field displays gibberish (e.g. 89:7A) | WinCC tag configured as Byte instead of Word, or as two independent bytes | Change tag type to Word (16-bit) and apply the BCD decode expression |
| Writing 14:35 silently fails, value reverts to 00:00 | One or more nibbles contain an illegal BCD digit (> 9) | Clamp the input fields to 0..23 h / 0..59 m and rebuild the word with the script above |
| Day-of-week checkboxes uncheck themselves | Bit 7 (Sunday+1) is being read as the Sunday value | Use only bits 0..6 of the byte; if the LOGO! firmware reports a packed byte, mask with 0x7F
|
| Parameter visible in VM mapping but not in HMI tag list | Target device in LOGO!Soft project is 0BA6 or older | Change File → Properties → Target Device to 0BA7 or later and re-transfer the program |
| Time updates with a one-second delay | Acquisition cycle set to > 1 s on the LOGO! connection | Set the LOGO! connection update time to 1 s (lowest) in the HMI device configuration |
| LOGO! rejects write with diagnostic buffer entry "Parameter error" | Time base value outside {1,2,3} | Constrain the TimeBase I/O field to a drop-down with exactly three entries |
Related Block Configuration Notes
The same BCD / Word pattern is reused by the Yearly Timer (B05) and the Astronomical Clock (B06), but the data footprint grows. A Yearly Timer exposes On-day / Off-day (each BCD-coded as DD.MM inside a Word) and an On-time / Off-time (HH:MM, also Word). Map all four parameters individually; the upper byte of each is the BCD-encoded month, the lower byte the day. The Astronomical Clock exposes a single Word whose upper byte is the sunrise hour, lower byte the sunset hour, both BCD-encoded.
Counter blocks (B08) and Runtime counter (B28) parameters map as Int and DInt respectively, so they are simpler to handle. The PI controller (B14) uses Word for setpoint and Word for the sensor input (0..1000) plus a Real for the output. Refer to the Variable Memory Configuration dialog data format column in each case.
Related Engineering References
- Siemens Knowledge Base 100782807 — Parameter VM Mapping (0BA7 and later)
- TIA Portal Help — Permitted data types for SIMATIC LOGO! RT Unified
- Snap7 open-source library — LOGO! memory reference
Which WinCC tag data type should I use for a LOGO! 0BA7 weekly timer on-time?
Configure the WinCC tag as a 16-bit Word pointing at the VM address reported in the LOGO!Soft Parameter VM Mapping dialog. The time is BCD-encoded (e.g. 14:35 = 0x1435), so the HMI must apply a BCD-to-binary decode before displaying the value as HH:MM.
Why does the on-time field read as two independent bytes instead of HH:MM?
This usually means the WinCC tag is configured as Byte rather than Word. The LOGO! kernel stores on-time and off-time as a 16-bit BCD value, occupying two consecutive VM bytes. Switch the tag type to Word and use a calculation expression to extract the two BCD digits per half-word.
How do I write a new on-time to the LOGO! from the HMI?
Convert the entered hours and minutes into a BCD word with the bit pattern described in this article, clamp them to 0..23 / 0..59 to avoid illegal BCD nibbles, then issue a single SetTagWord write to the VM address. The LOGO! does not return an explicit error code for an illegal BCD, so input validation in the HMI is mandatory.
What is the maximum number of parameters that can be mapped to VM on a 0BA7?
Up to 64 parameters per LOGO! Base Module, as documented in Siemens Knowledge Base entry 100782807. The cap is set by the LOGO! kernel, not by the HMI driver. If more parameters are required, add a second LOGO! Base Module or use an S7-1200 as a gateway.
Does the same approach work on LOGO! 0BA8 and 0BA9 with WinCC Unified?
Yes. The Parameter VM Mapping dialog behaves identically on 0BA8 / 0BA9, and WinCC Unified V17+ supports the same Bool / Byte / Int / DInt / Word data types through the dedicated SIMATIC LOGO! channel. The VM address layout produced by the mapping dialog is forward-compatible across all three hardware generations.