Reading ET200SP HA Channel & Module Diagnostics in PCS 7 V9.0 SP2

David Krause17 min read
Process ControlSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Reading ET200SP HA Channel & Module Diagnostics in PCS 7 V9.0 SP2

Channel-level and module-level diagnostics for SIMATIC ET 200SP HA remote I/O stations on a redundant CPU 410-5H automation system are generated automatically by the PCS 7 V9.0 SP2 Advanced Process Library (APL). The default @charts of every process tag already contain the channel driver instance, the alarm logic, and the operator messages required by Planning the configuration of an ET 200SP HA distributed I/O - no custom diagnostic block programming is required for the standard process alarms such as wire break, short circuit, underrange, and overrange.

This tutorial consolidates the PCS 7 APL mechanism, the underlying PROFINET IO diagnostic data records defined for the SIMATIC ET 200SP HA Technology Modules manual, and the asset-management view provided by the Maintenance Station option. The goal is to make module and channel diagnostics visible both in the WinCC operator station and on the diagnostic screens produced by the Maintenance Station, on a CPU 410-5H redundant AS running PCS 7 V9.0 SP2.

Scope. The procedures below target PCS 7 V9.0 SP2 with the APL V9.0 SP2 master data library installed. Lower APL revisions (V8.2, V9.0) carry the same block family but renamed or split blocks; verify the block type and version in the PCS 7 "Libraries" pane before applying the wiring shown.

1. System Prerequisites and Licensing

Before you plan diagnostics, the engineering station, the AS 410H pair, and the operator station must satisfy the following minimum configuration.

Component Required item Notes
Engineering Station (ES) SIMATIC PCS 7 V9.0 SP2, APL V9.0 SP2 Includes CFC, SFC, SCL compilers and the APL master data library
Automation System (AS) CPU 410-5H (6ES7410-5HX08-0AB0) firmware V8.2 or later Redundant pair with sync module V4.0+, fiber-optic sync cables
Head-end station IM 155-6 PN HA (6DL1155-2AU00-0PM0) firmware V6.0 or later One per ET 200SP HA rack, two for redundancy
I/O modules ET 200SP HA digital / analog / technology modules with channel diagnostics Check module faceplate: "D" in the article number indicates channel diagnostics
Operator Station (OS) WinCC Runtime V9.0 SP2, Maintenance Station Basic (no licence) or Standard (licence) Basic is included with the OS server licence
License model. Maintenance Station Basic is delivered with the PCS 7 OS and generates block icons only for PC stations, the AS, and PROFINET/PN IO network components. Maintenance Station Standard requires an additional count-based licence and is required to generate the block icons for the ET 200SP HA stations and their I/O cards. See PCS 7 manual "Compendium Part A - Process Automation", chapter 12 "Integrated asset management" for the exact entitlement matrix.

2. Automatic Diagnostics via APL Channel Drivers

When you compile the CFC chart of a process tag (e.g. Pcs7AnIn, Pcs7DiIn, Pcs7AnOu, Pcs7DiOu, Pcs7Mot, Pcs7Valve), PCS 7 does the following automatically:

  1. Generates the driver instance in the unit-level @chart (for example Unit1/AI_101 → instance DB DB1001).
  2. Generates the alarm and message logic including the standard process alarms "Failure", "Upper limit violated", "Lower limit violated", "Bad quality", and the channel-diagnostic alarms "Wire break", "Short circuit", "Underflow", "Overflow".
  3. Wires the channel-diagnostic input of the driver to the value status (QUALITY_BAD, bit 0x40 "Channel diagnostic available") of the input/output address from the PROFINET IO frame.
  4. Creates the corresponding WinCC message in the OS project, with the message class, priority, and the operator text configured in the APL block icon properties.

Therefore no additional program code is required in the @chart to obtain wire break, short circuit, and overflow alarms for a standard channel. The diagnostics are read by the PROFINET IO stack of the CPU 410-5H from the channel-specific diagnostic data records (DS 100) of the ET 200SP HA module and are forwarded to the OS as channel diagnostic alarms.

Do not add custom MSG_LOCK or ACK handling on channel diagnostics unless required. Doing so desynchronises the Maintenance Station state model from the OS message log.

3. APL Channel Driver Block Reference

The following APL blocks implement the standard channel driver with full diagnostic evaluation. Use the version that ships with the APL V9.0 SP2 master data library.

tbody>
Block Function Typical use on ET 200SP HA Diagnostic alarms emitted
Pcs7AnIn (FB 1869) Analog input 0/4-20 mA, RTD, TC AI 8xI 2/4-wire HA, AI 8xTC/RTD HA, AI 16xI 2-wire HA Wire break, Underflow, Overflow, High/Low limit, Bad quality
Pcs7DiIn (FB 1861) Digital input 24 V DC, NAMUR DI 16x24VDC HA, DI 16xNAMUR HA Wire break, Short circuit, Failure, Bad quality
Pcs7AnOu (FB 1870) Analog output 0/4-20 mA AO 4xI/P HA, AO 8xI HA Wire break, Short circuit, Bad quality
Pcs7DiOu (FB 1862) Digital output 24 V DC, relay DO 4x24VDC/2A HA, DO 8x24VDC/0.5A HA Wire break, Short circuit, Failure, Bad quality
Pcs7Mot (FB 1874) Reversing motor (forward / reverse / off) DO 4x24VDC HA + DI 16x24VDC HA feedback Contactor feedback failure, Thermal overload, Bad quality
Pcs7Valve (FB 1875) On/off valve with end-position feedback DO 4x24VDC HA + DI 16x24VDC HA feedback End-position deviation, Bad quality

For the full list of block numbers, signal pin names, and the runtime licence per channel driver see the PCS 7 V9.0 SP2 APL Function Manual shipped on the PCS 7 installation media (entry ID 109811210 in the Siemens Industry Online Support).

4. @Charts Architecture and Driver Instances

Every PCS 7 plant unit contains an automatically generated @chart (driver chart). The chart holds one instance of the channel driver per process tag of the unit and a single instance of MOD_PREP plus the S7 standard blocks OB_BEGIN, OB_END, and (if redundancy is enabled) RED_AGO / RED_ANA. A simplified view of a single unit is shown below.

Unit1 / @Unit1 (driver chart) MOD_PREP OB_BEGIN Pcs7AnIn (AI_101) FB 1869 Pcs7DiIn (DI_202) FB 1861 RED_AGO AS 410H redundancy Pcs7AnOu (AO_301) FB 1870 Pcs7DiOu (DO_401) FB 1862

To make the channel diagnostics visible in the OS, set the following attributes in the block icon properties of the channel driver:

  • Message class: Process - Failure or Process - Warning depending on the alarm category.
  • Operator text: &1 &2 failed: channel &3, slot &4 (substitutes the tag name, unit, channel and slot at runtime).
  • Acknowledgement: enabled for the "Failure" class, disabled for warnings such as wire break if the HCI / Maintenance policy is configured to treat them as a non-ack warning.

5. Module and Channel Diagnostics Data Records

The ET 200SP HA modules expose a defined set of PROFINET IO diagnostic data records. The CPU 410-5H reads them on demand and on diagnostic interrupt; the values are the source of the "Bad quality" bit and the channel-diagnostic alarms seen on the OS. The data records most relevant to operator-visible diagnostics are listed below; refer to the SIMATIC ET 200SP HA Technology Modules manual for the full set and the byte layout.

Data record Hex index Content Source / use in PCS 7
DS 0 0x8000 Standard diagnostics (module state, channel 0..63 status, channel group error) CPU 410-5H PROFINET stack; shows on OS via MOD_PREP and the IM 155-6 PN HA faceplate
DS 1 0x8001 Module identification (order number, serial, firmware, slot) Read with SFB 52 / SFB 81 on operator request
DS 12-15 0x800C-0x800F I&M 0..3 (identification & maintenance) Read with SFB 52; used by Maintenance Station Standard
DS 50 / DS 51 0x8032 / 0x8033 Module parameter (read / write) Used by HW Config of STEP 7 / TIA Portal
DS 92 0x805C Reference data for PROFINET diagnostics Internal - PROFINET stack
DS 94 0x805E Diagnostic interrupt (with channel-diagnostic structure) Triggered on alarm; read with SFB 52 RDREC
DS 100 0x8064 Channel diagnostics (per-channel status and channel error type) Source of the channel-level alarms in the OS
DS 192 0x80C0 Watchdog time of the slot Diagnostic - timeout indication
DS 200 0x80C8 Maintenance information (counters, lifecycle) Used by Maintenance Station Standard to render card status
DS 201 0x80C9 Maintenance information (extended) Optional, module-dependent
Hex indices are PROFINET IO standard. The actual index accepted by RDREC is the unsigned 16-bit value (0x8000..0x80FF) - not the decimal number - and the slot/IM index must match the device's HW identifier in the PROFINET IO device table.

6. Reading Diagnostics with SFB 52 / SFB 81

Although the standard process alarms are generated automatically, two scenarios still require an explicit read:

  1. Operator-triggered module information from a custom WinCC dialog.
  2. Custom maintenance logic that has to decide between two state categories (for example "warning" vs "failure") based on the maintenance information in DS 200.

Use the standard S7 system blocks - no proprietary block has to be written. The required SFBs are part of the CPU 410 firmware and are therefore available without a licence.

SFB Name Purpose Typical ID input
SFB 52 RDREC Read a data record (any index, including DS 0 / DS 1 / DS 12 / DS 100 / DS 200) ID := HW_ID(ET200SP HA slot) - decimal HW identifier from HW Config
SFB 53 WRREC Write a data record (e.g. command or parameter change) ID := HW_ID(slot)
SFB 81 RD_DPAR Read the parameter assignment of a module (per device, not per channel) ID := HW_ID(ET200SP HA head-end)
SFB 54 RALRM Receive an interrupt / alarm with the raw diagnostic data MODE := 1 (read full interrupt info)

A minimal Structured Text wrapper for reading the channel diagnostic record of a digital input module is shown below. The block can be instantiated as a function block in the unit chart or in a dedicated "diagnostics" chart at plant level.

FUNCTION_BLOCK FB_RdChannelDiag
VAR_INPUT
  hwId      : DWORD;   // HW identifier of the slot, e.g. DW#16#0000012C = 300
  recIndex  : BYTE;    // 100 = 0x64, channel diagnostics
END_VAR
VAR_OUTPUT
  status    : WORD;    // RET_VAL of RDREC, 0 = no error
  busy      : BOOL;
  done      : BOOL;
  error     : BOOL;
  diagBytes : ARRAY[0..63] OF BYTE;
END_VAR
VAR
  rdrec     : RDREC;   // SFB 52 instance
  start     : BOOL;
  i         : INT;
END_VAR

// request trigger
start := NOT busy AND NOT done;
rdrec(REQ := start,
      ID  := hwId,
      INDEX := WORD#16#0064,    // DS 100 = channel diagnostics
      MLEN := 64,
      VALID := done,
      BUSY  := busy,
      ERROR := error,
      STATUS := status,
      RECORD := diagBytes);

After a successful read, decode diagBytes using the channel-diagnostic structure documented in chapter "Diagnostics / Alarms" of the ET 200SP HA configuration manual. Channel error codes 0x0001..0x000F (short circuit, wire break, underflow, overflow, parameterisation error) map to the channel alarm bits used by the APL drivers and the WinCC message system.

Redundancy. Always call RDREC on the CPU 410-5H that currently owns the I/O. With the H-system firmware V8.2 or later, the PROFINET stack transparently routes the request to the active CPU, so a user block does not need to query RED_AGO.AS_ACTIVE first.

7. Maintenance Station: Basic vs Standard

The PCS 7 Maintenance Station is the asset-management view of the plant. It renders block icons for every AS, every PROFINET/PN IO device, and (with the Standard option) every ET 200SP HA station and I/O card, and updates the state in real time using the data records listed above.

Item Maintenance Station Basic Maintenance Station Standard
Licence No additional licence (included in OS server) Per-station licence (count-based)
AS block icons Yes (CPU 410-5H pair) Yes
PC-station block icons Yes (OS server, ES, network components) Yes
ET 200SP HA station block icon No Yes
ET 200SP HA I/O card block icons No Yes (DI, DO, AI, AO, technology modules)
Maintenance state machine (OK / Maintenance demanded / Maintenance required) Partial Full - based on DS 200 counters
WebNavigator / Information Server export Yes Yes (extended KPI set)

To enable the Maintenance Station Standard:

  1. In SIMATIC Manager, open the OS project, right-click the OS server and select Object properties → OS server → Maintenance Station.
  2. Tick Maintenance Station Standard and enter the licence key in the "Authorisation" tab.
  3. In HW Config of the AS, mark the IM 155-6 PN HA as "diagnostics-capable" and enable the data record reads on slot 0 and on every I/O slot.
  4. Compile the OS - the compilation step automatically creates the block icons in the standard picture @Maintenance.pdl and adds the necessary WinCC tags under the Diagnostics\ prefix.

8. Step-by-Step: Make Channel Diagnostics Visible in PCS 7 V9.0 SP2

  1. Compile the HW Config of the AS 410H with "Generate diagnostic data record reads = ON" for every ET 200SP HA head-end. The AS then reads DS 1, DS 12..15 and DS 200 cyclically (default 1 s).
  2. Insert the APL channel driver in the unit chart: Pcs7AnIn, Pcs7DiIn, Pcs7AnOu, Pcs7DiOu, Pcs7Mot, Pcs7Valve - or one of the type-specific derivatives. Compile the chart. PCS 7 generates the @chart with the driver instance and the MOD_PREP block.
  3. Set the message classes in the block icon properties. For channel diagnostics, the APL default of Process - Failure for wire break / short circuit and Process - Warning for underflow / overflow is appropriate for most process plants.
  4. Download the AS program to the H-system. The PROFINET IO stack synchronises the channel-diagnostic information to the active CPU and the partner.
  5. Compile the OS (full compile, not incremental). The new messages appear in the WinCC message configuration; the new variables appear under Diagnostics\<unit>\.
  6. Open the OS Runtime and acknowledge the test alarm triggered by pulling the sensor wire on a digital input channel. The corresponding message "Wire break DI_202 / channel 5" should appear in the message line and the Maintenance Station view should switch the block icon of slot 5 to "Maintenance demanded".
Verification tip. If the OS message line is silent but the value status of the input turns to bad, the diagnostic interrupt has been received but the message class is filtered out. Open WinCC Explorer → "Message configuration" and check the bit for the channel diagnostic error in the "Channel diagnostics" message block.

9. Verification Checklist

Run the following verification matrix before signing off the diagnostics configuration on a CPU 410-5H AS.

# Test Expected result Tool
1 Open HW Config → "Online → Accessible nodes" on the AS IM 155-6 PN HA visible with firmware and order number STEP 7 V5.6 + HSP
2 Disconnect one sensor on a digital input channel OS message "Wire break" appears within < 1 s, Maintenance Station icon turns yellow OS Runtime
3 Force a channel to exceed 20.5 mA on an AI 4-20 mA channel OS message "Overflow" appears, value clamps at 21 mA with quality "bad, upper limit violated" OS Runtime + maintenance view
4 Simulate slot failure by removing a module OS message "Module failure", Maintenance Station icon turns red, redundant CPU stays in master OS Runtime + Maintenance view
5 Trigger a CPU stop on the standby CPU 410-5H No spurious channel diagnostic messages appear (PROFINET stack filters on the standby CPU) OS Runtime
6 Trigger a CPU stop on the master CPU 410-5H Failover completes in < 700 ms, channel diagnostics continue on the new master without operator intervention OS Runtime + AS switchover log
7 Read DS 100 of the AI slot with SFB 52 from a custom block Status word = 0 (no error), VALID goes high within 50 ms STEP 7 online monitor / SCL debug

10. Troubleshooting Matrix

Symptom Likely root cause Countermeasure
No message on the OS for a known wire break Module is configured in HW Config without "Channel diagnostics = enabled" Open the slot properties, tick "Channel diagnostics", re-download the HW Config and the AS program
Message appears, but the Maintenance Station icon stays green Maintenance Station Standard is not licensed Activate the licence under OS server → Object properties → Maintenance Station, recompile the OS
Channel diagnostic only on one CPU of the H-system Diagnostic interrupt blocked by user-acked MSG_LOCK on the standby CPU Remove the MSG_LOCK input on the APL driver or wire it to the RED_AGO.AS_ACTIVE signal
RDREC returns status W#16#80A1 Negative acknowledgement, slot not accessible Check the HW identifier, ensure the slot is owned by the master CPU. Verify the head-end has the latest IM 155-6 PN HA firmware
RDREC returns status W#16#80B1 Index out of range The data record index is 16-bit (0x8000-0x80FF). Re-check the INDEX parameter, not the decimal number
Overflow alarm appears on every channel of a module Common-mode voltage on the AI reference ground; module is in "voltage measurement" but wired in current Wire the channel as 0/4-20 mA, configure measuring range "2-wire / 4-wire transducer" in HW Config, re-download
Diagnostic buffer of the CPU 410-5H is full of "Module removed / inserted" events Loose D-sub connector on the front connector of the ET 200SP HA terminal block Re-tighten the front connector, re-seat the terminal block until the latch audibly clicks
Wire-break alarm is missing on a NAMUR input channel NAMUR channel must be explicitly configured as "NAMUR", not as "24 V DC standard" Set the channel type to "NAMUR" in HW Config slot properties, re-download the HW Config

11. Field-Commissioning Notes

  • CFC compile order. Compile the unit charts before the @chart is generated. The @chart depends on the chart-folders of the unit; an out-of-order compile creates a @chart with missing channel-driver instances.
  • I&M data. Fill the I&M 1, I&M 2, I&M 3 fields per module before the first cold start. The Maintenance Station Standard depends on I&M 1 ("Location") to render the asset tree correctly.
  • OS redundancy. If the OS server is redundant, the Maintenance Station views are mirrored automatically. Verify the Diagnostics\ tag prefix is identical on both servers, otherwise messages from the partner server will be tagged as "Unknown".
  • PROFINET update time. The default update time of 1 ms for the IM 155-6 PN HA may be too aggressive for analog channels. Use 2 ms for AI/AO channels in the process industry, and 1 ms only for fast DI/DO. See Reading out the diagnostics in STEP 7 (TIA Portal).
  • Cybersecurity. Channel diagnostic reads use plain S7 communication. If the AS is on a security-zoned network, open the firewall only for S7 port 102 and the PROFINET-RT class 1 multicast ranges.

FAQ

Which PCS 7 block reads ET 200SP HA module diagnostics automatically?

None of the user blocks does it manually. The PROFINET IO stack of the CPU 410-5H reads the diagnostic data records of every ET 200SP HA slot, and the APL channel drivers (Pcs7AnIn, Pcs7DiIn, Pcs7AnOu, Pcs7DiOu, Pcs7Mot, Pcs7Valve) in the unit @chart evaluate the value status and emit the channel-diagnostic alarms. No additional block has to be programmed for the standard alarms.

Can I read a specific data record (for example DS 100) from an ET 200SP HA module?

Yes. Use SFB 52 "RDREC" with the slot's HW identifier and the 16-bit PROFINET IO index of the data record (for example 0x0064 for DS 100, channel diagnostics). SFB 81 "RD_DPAR" reads the parameter assignment of the head-end module, and SFB 54 "RALRM" returns the full interrupt data of a diagnostic interrupt.

What is the difference between Maintenance Station Basic and Standard?

Maintenance Station Basic is included with the OS server licence and generates block icons only for the AS, the PC stations and the network components. Maintenance Station Standard requires an additional per-station licence and additionally generates block icons for the ET 200SP HA stations and every I/O card, with a full maintenance state model based on data record 200.

Does diagnostics work on a redundant CPU 410-5H pair?

Yes. With H-system firmware V8.2 or later the PROFINET stack synchronises the channel-diagnostic state to the partner CPU in the background, and the application code does not need to be aware of which CPU is currently the master. The standby CPU does not generate duplicate diagnostic interrupts for the same I/O.

Where can I get a sample project that uses APL diagnostics on ET 200SP HA?

Siemens does not ship a "PCS 7 with ET 200SP HA diagnostics" sample as a single archive. Build the sample yourself by creating a unit, dropping the APL channel driver into its chart, compiling the unit, and enabling Maintenance Station Standard in the OS server. The PCS 7 V9.0 SP2 APL Function Manual describes the inputs, outputs and message classes of every APL channel driver, and the ET 200SP HA configuration manual describes the diagnostic data records that the drivers evaluate.

What does status W#16#80A1 of SFB 52 mean on an ET 200SP HA slot?

W#16#80A1 is a negative acknowledgement and means that the slot is currently not accessible - usually because the slot is in the partner CPU, the module is in startup, or the HW identifier in the call does not match the slot. Verify the HW identifier, wait until the module is back in operation, and call RDREC again.

Back to blog