Diagnostic Buffer Architecture on S7-300/400 CPUs
The diagnostic buffer is a non-volatile circular buffer resident in every S7-300 and S7-400 CPU (including CPU317-2 DP/PN). It records every operating-mode transition, error entry, I/O fault, communication event, OB call, and user-defined diagnostic event as a time-stamped entry. The buffer survives power cycles and STOP/RUN transitions, making it the first source an S7 programmer turns to when troubleshooting. The buffer depth is firmware-dependent: typical CPU31x devices provide 100 entries, while newer CPU31xT/PN variants can provide 200 or more. Entries are stored oldest-first; a read request that exceeds the buffer depth returns entries from the most recent to the oldest in sequence.
Two official paths exist for retrieving buffer entries:
- SFC51 "RDSYSST" (Read System Status List) in the user program, used inside STEP 7 V5.x or compatible runtime environments on the CPU317-2.
- Online & Diagnostics view in TIA Portal, which is the recommended path for S7-1200/1500 and is also usable against S7-300/400 CPUs that support an online connection from a TIA Portal higher than V13. The TIA Portal help describes this path at TIA Portal S7-1200 manual collection - diagnostics buffer.
SFC51 (RDSYSST) Read Fundamentals
SFC51 belongs to the standard library of system functions embedded in every S7-300/400 CPU. It returns a partial list (SSL partial list) of the system status list (SZL). To read the diagnostic buffer entries the partial list identifier SSL_ID is set to W#16#00A0 and the INDEX to W#16#0000 for the complete list of available entries.
| Parameter | Decl. | Type | Meaning |
|---|---|---|---|
| REQ | INPUT | BOOL | Rising edge starts the read job. |
| SZL_ID | INPUT | WORD | SSL partial list ID. Use W#16#00A0 for diagnostic buffer entries. |
| INDEX | INPUT | WORD | Sub-index. W#16#0000 reads all entries supported by the CPU. |
| RET_VAL | OUTPUT | INT | Function return value / error code (see SFC51 manual). |
| BUSY | OUTPUT | BOOL | TRUE while the asynchronous read is in progress. |
| SZL_HEADER | OUTPUT | STRUCT | LENTHDR (WORD): length of one data record in bytes. N_DR (WORD): number of data records returned. |
| DR | OUTPUT | ANY | Pointer to the destination area; must be large enough for all records returned. |
RET_VAL values of interest when reading W#16#00A0:
| RET_VAL (decimal / hex) | Meaning |
|---|---|
| 0 / W#16#0000 | No error. |
| 1 / W#16#0001 | No current information available (e.g., after power-up). |
| 8090 / W#16#8090 | Specified SSL_ID/INDEX combination is not supported by this CPU/firmware. |
| 80A1 / W#16#80A1 | Negative acknowledgement when reading. |
| 80B0 / W#16#80B0 | SFC51 cannot read because the diagnostic buffer is being updated by a higher-priority process. |
| 80B1 / W#16#80B1 | SFC51 not permitted because of operating mode (CPU in STOP, password-protected, or system is currently writing the buffer). |
| 80C1 / W#16#80C1 | Buffer overflow / read error during runtime. |
For full error-code context, see the STEP 7 System and Standard Functions reference manual on the Siemens Industry Online Support portal at support.industry.siemens.com (search term "SFC51 RDSYSST").
SSL Partial List W#16#00A0 Data Record Layout
Each returned data record of partial list W#16#00A0 is 10 words (20 bytes) long. The SZL_HEADER reports the length-of-data-record and the number-of-data-records, so a buffer area of size N_DR x LENTHDR must be reserved before calling SFC51.
| Field | Word Offset | Width (Words) | Meaning |
|---|---|---|---|
| Event ID | 0 | 1 | Hex-encoded event class + identifier. See decoding section below. |
| Info field | 1..5 | 5 | Event-dependent. Typical content: logical base address of the faulty I/O, OB number, rack/slot, BStack pointer, parameter assignment block identifier, or software error code. |
| Time stamp | 6..9 | 4 | Internal time stamp - resolved to date/time via SFC1 "READ_CLK" or SFC6 "RD_SINFO_T". |
The "10 words" data-record length is constant for the diagnostic buffer; only N_DR changes between CPU firmware revisions. Always allocate at least 200 records (10 words x 200 = 2000 words = 4000 bytes) of DB area to capture the largest CPU31x diagnostic buffer.
Decoding the Event ID Field
The Event ID (Word 0 of each record) is a 16-bit value split into a high byte (event class) and a low byte (event identifier). Siemens documents the encoding in the "Standard and System Functions" reference manual.
| Bits 12..15 (high nibble) | Event Class |
|---|---|
| 0 / 1 | Standard OB events (startup, restart, priority class, OB1 cycle). |
| 2 | Error/fault events (STOP transitions, OB not loaded, time errors, rack/stop errors). |
| 3 | Synchronous errors (OB121 programming error, OB122 I/O access error). |
| 4 | Mode transitions (STOP, RUN, HOLD, link-up/link-down). |
| 5 | Communication events (CP, GD, S7 connection diagnostics). |
| 6 | H/F (fail-safe) events for F-CPUs. |
| 7..9 | Diagnostic events, I/O fault, hot-swappable module fault. |
| A..F | User-defined events triggered by SFC52 / SFC107. |
Reference example given in the original engineering discussion: EventID = W#16#4302. High byte 0x43 indicates the diagnostic-events class; low byte 0x02 indicates "IO fault - module has triggered diagnostic interrupt and OB82 was called". The Info field of this entry normally contains the logical base address of the faulted channel in the high word and the channel status bits in the low word.
Other frequently encountered IDs on CPU317-2 in the field (cross-check against your STEP 7 version's event database):
| EventID (hex) | Plain-text equivalent (Siemens database) |
|---|---|
| W#16#2521 | CPU has gone into STOP (programming error in OB that is not loaded). |
| W#16#3501 | Parameter assignment error (SDB inconsistency, e.g., module removed or mismatched). |
| W#16#357E | Interface error on the DP/PN interface. |
| W#16#3901 | Operating-mode change: RUN/STOP/HOLD transition. |
| W#16#4302 | IO fault - module diagnostic interrupt (OB82 active). |
| W#16#4949 | Diagnostic interrupt status change for an HART/PROFIBUS slave. |
| W#16#7378 | Communication: S7 connection established / torn down. |
| W#16#8302 | Module plugged/removed event on ET 200. |
Reading the Diagnostic Buffer with SFC51 - Sample STL/SCL Code
The following SCL block (FC100 "DiagBufRead") reads the entire diagnostic buffer of a CPU317-2 into a user DB (DB100). The same pattern can be implemented in STL when block names are limited.
FUNCTION FC100 : VOID
VAR
fbRDSYSST : SFC51; // system function instance
bStart : BOOL; // edge-triggered start
iRetVal : INT; // SFC51 return value
bBusy : BOOL; // SFC51 still reading
szlHeader : STRUCT
LENTHDR : WORD;
N_DR : WORD;
END_STRUCT;
aDiagBuf : ARRAY[0..199] OF WORD; // 200 records x 10 words each
tStartTime : DATE_AND_TIME;
END_VAR
BEGIN
IF bStart AND NOT bBusy THEN
iRetVal := SFC51.REQ := TRUE;
SFC51(SZL_ID := W#16#00A0,
INDEX := W#16#0000,
RET_VAL=>iRetVal,
BUSY=>bBusy,
SZL_HEADER=>szlHeader,
DR:=aDiagBuf);
// After completion aDiagBuf contains szlHeader.N_DR records.
// Each record: Word 0 = EventID, Words 1..5 = Info, Words 6..9 = Time stamp.
END_IF;
END_FUNCTION
For STL implementation, call SFC51 once with REQ edge, then poll BUSY. When BUSY falls and RET_VAL = 0, the data is in the destination DB and can be copied to an array indexed by record number. Reserve 4000 bytes of DB100 (DB100.DB\_W0 through DB100.DB\_W3999) and pass DR := P#DB100.DBX0.0 WORD 4000.
Displaying Events in WinCC Using the Text Library Method
This is the simplest path when the operator needs to see a short, fixed-language description. The WinCC project is set up with a Text Library entry for every Event ID of interest, and the EventID value stored in a WinCC tag drives an indirect reference into that library.
-
Create the WinCC tags. In WinCC Explorer > "Tag Management", add the following tags (driver WINCC S7-MPI/TCP channel or SIMATIC S7 PROTOCOL SUITE):
-
DiagBuf_EventID- WORD, polls DB100.DBW0 (EventID word of record 0). -
DiagBuf_Info1throughDiagBuf_Info5- WORD each, polls DB100.DBW2..DBW10. -
DiagBuf_Time- DATE_AND_TIME, polls DB100.DBD12..DBD18.
-
-
Build the Text Library. Open WinCC Graphics Designer, draw a static text field. In its "Text" property, choose "Dynamic" > "Indirect" and link it to
DiagBuf_EventID. Add entries in the Text Library for every expected Event ID (e.g., index 17154 decimal = 0x4302 mapped to "IO fault - OB82 called"). -
Optional: configure a WinCC alarm. In Alarm Logging, add a new message that fires when
DiagBuf_EventIDchanges value. Map the alarm text to the same Text Library lookup so the operator can scroll the historical alarm list. - Cycle trigger. Use an OB35 call on the CPU to copy one buffer record per cycle into the polled tag area, e.g., DB100.DBW0 = current record number, and a WinCC internal script or an SFC call rotates the record pointer.
The limitation of this approach is straightforward: it scales only as far as the Text Library grows. For a CPU317-2 with up to 100 diagnostic events per shift, that is manageable; for a fail-safe system with several hundred unique Event IDs the project becomes unwieldy.
Displaying Events in WinCC Using Report System Error
Report System Error (RSE) is the manufacturer-recommended path because it leverages the event database that STEP 7 already ships with. The CSE (Component based S7 Error) and SFM (S7-Fault Message) block pair are generated automatically during compile and provide a curated, WinCC-ready message set without the engineer hand-keying Event IDs.
- Open the S7 project in STEP 7 V5.x. Open HW Config and right-click the CPU317-2 slot. Select "Report System Error..." from the context menu.
- Enable RSE. Activate "Generate block for report system error". Default FB names are FB126 "CSE\_LOCAL" for non-F-CPU setups and FB127 for global distribution.
- Choose OBs and FMs to monitor. In the dialog, select which organizational blocks (OB80..OB87, OB100, OB121/122, OB82) and which fault messages to surface. STEP 7 will populate the SFM DB (DB126/DB127) with the corresponding message texts and the WinCC integration files.
- Compile and download. Compile HW Config, then download the HW configuration plus blocks. Verify in NetPro that the AS-OS connection is set to "S7 fault messages: Yes".
- Integrate into WinCC. In WinCC Explorer > "OS Project Editor", run "OS Project Editor Wizard" with the option "S7 Fault Messages: Yes". The wizard imports the alarm texts, generates the WinCC tags that map to SZL 0x00A0, and builds the Alarm Logging view automatically.
- Test the path. Force a diagnostic event (pull a module, change a parameter, trigger an OB82) and verify the message appears in WinCC Runtime with timestamp, Event ID, and module address.
Displaying Events with a Raw Tag ReadSZL
For projects that want the entire diagnostic buffer payload (not just the curated RSE list), WinCC can poll SZL 0x00A0 directly through a Raw tag with the S7CHN driver using the ReadSZL mechanism. This bypasses user code entirely and is useful when the S7 program cannot be modified (e.g., on a vendor-supplied CPU).
- In WinCC Tag Management, add a tag of type "Raw" with the SIMATIC S7 PROTOCOL SUITE channel.
- Select "RAW" datatype and configure the SZL request: SZL_ID = 0x00A0, INDEX = 0x0000.
- Map the resulting 4000-byte payload into a "Tag-Set". WinCC exposes the EventID, Info words, and time stamp as sub-tags via raw slicing.
- Bind Graphics Designer fields to the corresponding sub-tags.
This path eliminates the SFC51 user code, but it makes the WinCC project dependent on the S7CHN driver, which is not available on every WinCC variant. Confirm with the WinCC Information System that the SIMATIC S7 PROTOCOL SUITE > RAW channel is licensed for your runtime.
TIA Portal Diagnostics Buffer View (Reference for Migration)
If the long-term plan is to migrate from CPU317-2 (S7-300) to S7-1200/1500, the equivalent path is the "Online & Diagnostics" view in TIA Portal. The diagnostics buffer is reached via "Online & diagnostics" of the target device, then "Diagnostics > Diagnostics buffer". The buffer is read-only, sorted newest-first, and presented in a tabular view with Event ID, plain-text description, time stamp, and info fields.
For S7-1200, the same diagnostics buffer concept exists but the read function changes from SFC51 to the S7-1200 instruction "Get\_Diag" or to "RD\_REC" / "RD\_LOC" reading of record 0x00A0. The CPU317-2 path using SFC51 is the only path that works against the S7-300 firmware line. Reference: TIA Portal S7-1200 manual collection - diagnostics buffer.
Verification and Commissioning
-
Force a known event. Pull a configured DI module on the ET 200M attached to the CPU317-2. Expect a new entry with EventID =
W#16#4302and Info Word 1 = logical base address of the module. - Check SFC51 RET_VAL. Confirm 0 on the read. Anything in 0x80xx range means the call did not complete - check BUSY and trigger again.
-
Confirm WinCC tag value. The polled
DiagBuf_EventIDtag in WinCC should equal the EventID stored in DB100. Use WinCC Online Trend Control to monitor the tag and confirm one entry per cyclic interrupt. - Confirm text rendering. The Text Library entry index 0x4302 should display "IO fault - OB82 called" (or your localization). If the field remains blank, the Text Library index does not match the EventID value - cross-check decimal vs. hex indexing.
- Test RSE path. If using Report System Error, verify the WinCC alarm appears with timestamp and module address. If the alarm does not appear, verify the AS-OS connection has "S7 fault messages: Yes" and that DB126 (or DB127) is loaded.
- Document the Event IDs in scope. Maintain a project-specific mapping table from Event ID to operator-facing language and to maintenance action. The STEP 7 "PLC -> Diagnostic Buffer" view is the authoritative source.
Troubleshooting Matrix
| Symptom | Likely Root Cause | Remediation |
|---|---|---|
| SFC51 RET_VAL = W#16#8090 | SSL_ID/INDEX combination not supported by this CPU/firmware. | Verify W#16#00A0 and W#16#0000. Check CPU firmware release; very old firmware (< 2.0) may not support the full list. |
| SFC51 RET_VAL = W#16#80B1 | CPU in STOP or buffer is being updated concurrently. | Wait until BUSY is reset; if CPU is in STOP, place the call inside OB100 or a warm-restart OB. |
| WinCC tag stays zero | Tag address wrong or DR area not big enough. | Verify the WinCC tag points to the same DBW that SFC51 writes. Confirm DR is sized to LENTHDR x N_DR bytes. |
| WinCC text shows only the EventID hex | Text Library entry not defined for that EventID. | Add the missing index to the Text Library. For projects with many IDs, switch to RSE. |
| EventIDs visible in STEP 7 but not in WinCC | User disabled the CPU diagnostic messages (CPU properties -> "Report System Error: No"). | Enable "Report System Error" again or re-establish the S7 connection attribute. |
| Events appear duplicated | OB1 calls SFC51 every cycle instead of an edge. | Move the call to OB35 or trigger it via a flag toggled by a WinCC button. |
| Time stamp wrong by hours | CPU clock not synchronized. | Call SFC1 / SFC48 to read CPU clock; trigger time sync via WinCC Time Synchronization or NTP. |
| User wants to clear the buffer | SFC51 cannot clear entries. | Buffer is circular; only a memory reset or buffer overflow clears entries. Document which event caused the overflow. |
FAQ
What SSL_ID do I use with SFC51 to read the CPU317-2 diagnostic buffer?
Use SSL_ID W#16#00A0 with INDEX W#16#0000. Each data record is 10 words long: 1 word EventID + 5 words Info + 4 words time stamp.
Why does my SFC51 RET_VAL show W#16#8090?
The SSL_ID/INDEX combination is not supported by the CPU/firmware. Confirm the firmware version supports W#16#00A0 and re-check the spelling of the constants (e.g., W#16#00A0, not W#16#A0).
Can the user program decode the EventID to plain text without STEP 7?
Not practically. The mapping from EventID to text is shipped in STEP 7 / TIA Portal event databases and is not published in a redistributable form. Use the WinCC Text Library, Report System Error, or the SIMATIC S7 PROTOCOL SUITE Raw tag to leverage these databases from WinCC.
How many records does SFC51 return for the CPU317-2?
Typical CPU31x devices return 100 records; newer firmware can return 200. Use the SZL_HEADER returned by SFC51 to determine the actual count (N_DR) and size (LENTHDR) of your destination buffer.
Does Report System Error require a separate S7 connection?
No new connection is required, but the AS-OS connection must have the "S7 fault messages" attribute set to "Yes" in NetPro. Without this attribute the SFM blocks on the CPU cannot push events to the WinCC Runtime.
Can I use this approach on an S7-1200/1500?
No - SFC51 is supported only on S7-300/400. On S7-1200/1500 use the "Get_Diag" instruction, "RD_REC" with record 0x00A0, or the Online & Diagnostics diagnostics buffer view in TIA Portal.