Reading Siemens LOGO! RTC Time on KINCO HMI via VM Addresses

David Krause11 min read
HMI / SCADASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Reading Siemens LOGO! Real-Time Clock on a KINCO HMI via VM Addresses

Overview

When integrating a Siemens LOGO! 8 (0BA8) logic module with a third-party HMI such as a KINCO MT/GL series panel, displaying the LOGO!'s internal real-time clock (RTC) on the HMI screen is not automatic. Unlike a SIMATIC Comfort or Basic Panel that imports a LOGO! tag list directly through TIA Portal / WinCC, a third-party panel must address the LOGO!'s Variable Memory (VM) area directly using the S7 communication protocol over Ethernet TCP/IP. The challenge is that the LOGO! RTC is not exposed as a single "datetime" tag – it is split across byte-level VM addresses in two parallel formats: integer (decimal) and BCD.

This article documents the precise VM address map for the LOGO! RTC (VB985–VB998), the S7 Ethernet setup on both the LOGO! Soft Comfort project and the KINCO HMI, the correct KINCO Number Component configuration (data type, scaling, and range), and the critical write-protection step that prevents the HMI from accidentally advancing the LOGO! clock whenever the operator taps the field.

Scope: This procedure applies to LOGO! 8 (6ED1052-xxx08-0BA8) and LOGO! 8.3 (6ED1052-xxx08-0BA3) controllers. LOGO! 7 (0BA7) and earlier do not expose the same VM layout.

Prerequisites

  • Siemens LOGO! 8 (0BA8) base module with firmware 1.08.x or later, or a LOGO! 8.3 module.
  • LOGO! Soft Comfort V8.x programming tool (current release is V8.3) – download from the Siemens LOGO! 8 system manual landing page.
  • KINCO HMI from the MT, GL, or HMIworks-compatible series with the matching Kinco DTools configuration software (current release: Kinco DTools V3.5+).
  • Ethernet switch or direct patch cable (LOGO! supports Auto-MDI/MDIX).
  • Both devices configured with static IP addresses on the same subnet (e.g., LOGO! 192.168.0.10, KINCO 192.168.0.20, mask 255.255.255.0).

LOGO! VM Memory Map for the Real-Time Clock

The LOGO! 8 internal variable memory is organized as a byte-addressable area in which the RTC is mirrored in two parallel encodings: a decimal/integer view (VB985–VB990, VB998) and a BCD view (VB991–VB996). The integer view is most convenient for KINCO Numeric Displays because it does not require hexadecimal conversion on the HMI side. The BCD view is the raw value that the LOGO! RTC functions (Weekly Timer, Yearly Timer, Astronomical Clock) read internally.

Decimal / Integer RTC Block (VB985–VB990, VB998)

Address Contents Encoding Range (decimal)
VB985 Year (last 2 digits) Integer 0–99
VB986 Month Integer 1–12
VB987 Day of month Integer 1–31
VB988 Hour Integer 0–23
VB989 Minute Integer 0–59
VB990 Second Integer 0–59
VB998 Day of week Integer 1 (Sun) – 7 (Sat)

BCD / Hexadecimal RTC Block (VB991–VB996)

Address Contents Encoding Range (raw decimal equivalent)
VB991 Year (last 2 digits) BCD 0x00–0x99 (0–153)
VB992 Month BCD 0x01–0x12 (1–18)
VB993 Day of month BCD 0x01–0x31 (1–49)
VB994 Hour / Minute (combined) BCD word 0x0000–0x2359 (0–9065)
VB995 Minute BCD 0x00–0x59 (0–89)
VB996 Second BCD 0x00–0x59 (0–89)
Address VB997 / VW997: Some documentation and field experience report that VW997 (16-bit word starting at VB997) is used to read the Seconds field as a BCD value. Because the seconds byte occupies only the low byte of VW997, the upper byte will read back as 0x00, giving a clean 0–89 decimal range. Either VW994 (hours/minutes packed) or VW997 (seconds) can be used as the KINCO source – both are valid.

Why two formats?

The integer block (VB985–VB990) is convenient for external visualization because the value read is already in engineering units. The BCD block (VB991–VB996) is the internal representation that the LOGO! firmware uses when comparing the RTC against Weekly Timer, Yearly Timer, and Astronomical Clock blocks. If you write to the integer block the LOGO! firmware ignores the change; if you write to the BCD block the firmware will accept it – which is the exact reason accidental writes from a mis-configured HMI can advance or freeze the LOGO! clock.

Step-by-Step: LOGO! Soft Comfort Project Configuration

  1. Enable Ethernet on the LOGO! In the LOGO! Soft Comfort project, open Tools → Ethernet Connections. Enable the S7 protocol on port 102 (default). Set the LOGO! IP address (e.g., 192.168.0.10) and subnet mask. Confirm Allow S7 Communication is checked.
  2. Configure the RTC block. Although the LOGO! RTC runs internally without an explicit block, ensure the System Clock / Real-Time Clock parameter is enabled under File → Properties → Time. The LOGO! uses an onboard battery-backed RTC; without a battery, the clock resets on every power cycle.
  3. Do NOT bind any FBD element to the RTC VM addresses. The VM addresses VB985–VB998 are reserved for the system RTC. Do not assign them to user variables or markers in the Variable Memory table.
  4. Compile and download the LOGO! Soft Comfort program to the controller via Ethernet or USB.

Step-by-Step: S7 Ethernet Communication Setup on KINCO HMI

  1. Open Kinco DTools and create a new project. Select the actual KINCO panel model (e.g., MT4434TE) so the offline/runtime tag database size matches the hardware.
  2. Under Project → HMI Attribute, set the HMI IP address (e.g., 192.168.0.20), subnet mask, and gateway.
  3. Add a new PLC / Controller link: Edit → Device/PLC. Select the manufacturer Siemens and the driver S7-200 (TCP/IP) over Ethernet. (This is the standard driver used for LOGO! 8 because the LOGO! implements the S7-200 communication subset.)
  4. Set the Target IP to the LOGO! address (192.168.0.10) and the port to 102. Leave CPU slot = 0 and Rack = 0 – LOGO! accepts these defaults.
  5. Verify connectivity with the Online Simulation tool in Kinco DTools. The driver must report Connected within 5 seconds.

Step-by-Step: KINCO Number Component Configuration for the RTC

The KINCO toolbox provides a Number Component (also called Numeric Display / Numeric Input) that can read a single 16-bit word from the controller. Because KINCO tags are aligned to 16-bit VW (word) and 32-bit VD (double-word) boundaries – there is no pure V byte address – every LOGO! RTC field must be mapped to a VW or VD address.

Displaying Hours and Minutes (VW994, BCD-packed)

  1. Drop a Number Component onto the screen.
  2. In Basic Attributes set the address to VW994. The KINCO driver will read the BCD-encoded word (e.g., 0x1437 = 5175 decimal for 14:37).
  3. In Numeric Data set: Format = Hexadecimal, Word Length = WORD, Integer Digits = 2, Decimal Digits = 2, Min = 0, Max = 9065 (corresponds to 0x2359 = 23:59).
    Some integrators enter Max = 9049; this is an approximation safe for runtime because the firmware clamps out-of-range BCD writes. Use 9065 for headroom.

Displaying Seconds (VW997 or VW996)

  1. Drop a Number Component and set the address to VW996 (or VW997 – both contain the seconds byte).
  2. Set Format = Hexadecimal, Word Length = WORD, Integer Digits = 2, Decimal Digits = 2, Min = 0, Max = 89 (0x59).

Displaying Month and Day (VW992, BCD-packed)

  1. Drop a Number Component with address VW992.
  2. Set Format = Hexadecimal, Word Length = WORD, Integer Digits = 2, Decimal Digits = 2, Min = 0, Max = 4657 (0x1231 = December 31).

Displaying the Day of Week (VB998 / VW998, integer)

  1. Drop a Number Component with address VW998.
  2. Set Format = Decimal (not hex – this is an integer field), Word Length = WORD, Integer Digits = 1, Decimal Digits = 0, Min = 1, Max = 7. Add a Label Library mapping 1 → SUN, 2 → MON, 3 → TUE, 4 → WED, 5 → THU, 6 → FRI, 7 → SAT.

Critical: Disable "Enable Input" on Every RTC Field

This is the most common cause of a frozen or fast-running LOGO! clock on a KINCO integration. When Enable Input is checked on a Number Component bound to a writable LOGO! VM address, KINCO continuously writes the field's value back to the controller. Because the LOGO! RTC blocks (VB991–VB996) are write-active, every poll cycle overwrites the actual clock with whatever value the HMI operator last entered – or with zero if the field is empty. The result is the clock stops, jumps, or runs at wrong rate.

Procedure:

  1. Select each Number Component that displays an RTC field.
  2. In Basic Attributes, uncheck Enable Input.
  3. Confirm the component is set to Read Only display mode (the icon on the toolbar should not show the input cursor).
  4. Repeat for every RTC field. Do not skip this step – the S7 driver does not filter writes on the KINCO side.

Verification Procedure

  1. Power-cycle the LOGO! with a battery installed – the clock should retain the time. If the clock resets to 00:00:00 01.01.2000, replace the LOGO! backup battery (article number 6ES7291-8BA20-0AA0 for LOGO! 8).
  2. From the LOGO! onboard display, navigate to Set → Time/Date and confirm the current time. Note the minutes value.
  3. On the KINCO screen, observe the same field updating within one second of the LOGO! onboard display.
  4. Wait 5 minutes and confirm the value advanced correctly (no skips, no jumps).
  5. Touch the Number Component on the KINCO screen – if a numeric keypad appears, Enable Input is still active; uncheck it.
  6. Use the KINCO Online Simulation trace to log VW994 over 60 seconds and confirm the value matches the LOGO! clock.

Troubleshooting Matrix

Symptom Likely Cause Diagnostic Resolution
HMI shows 0 or constant value S7 driver not connected Kinco DTools Online → Status Verify port 102 open on LOGO!, correct IP, no firewall
Time is wrong by hours Reading VW994 as decimal, not hex Numeric Data format Switch format to Hexadecimal for BCD fields
Clock freezes when HMI is touched Enable Input is checked Component Basic Attributes Uncheck Enable Input on every RTC field
Clock advances randomly HMI writing zero to seconds Same as above Uncheck Enable Input; verify Min/Max scaling
Garbled date (e.g., 25th month) Reading VW992 as integer Numeric Data format Switch format to Hexadecimal
Day of week shows 0 Address off-by-one Monitor VB998 Confirm address is VB998 / VW998, not VB997
HMI shows stale value after LOGO! reboot KINCO driver caching Watchdog timeout Set acquisition cycle ≤ 500 ms
Only integer fields work (BCD fields read 0) Driver set to S7-300 instead of S7-200 Device / PLC config Change driver to Siemens S7-200 TCP/IP

Alternative Approach: Read Integer Block Instead of BCD Block

If your KINCO operator interface does not support a Hexadecimal Numeric Data format (older Kinco DTools versions), read the integer RTC block (VB985–VB990) instead. Each field is one byte, so combine two fields into a VW by reading:

  • VW985 – Year/Month (high byte = year, low byte = month)
  • VW987 – Day/Hour
  • VW989 – Minute/Second

Format = Decimal, Word Length = WORD, Integer Digits = 2, Decimal Digits = 2. The integer block is read-only from the LOGO! firmware's perspective, so accidental Enable Input is harmless.

Caution with the integer block: While the LOGO! does not write the RTC into VB988-VB990 every scan, it does refresh them once per second. To avoid mid-update reads, set the KINCO acquisition cycle to 1000 ms or slower.

Field-Proven Caveats and Edge Cases

  • LOGO! 8.3 firmware 1.09.x or later introduces an additional RTC mirror in the cloud-connectivity tag namespace; the VM addresses documented above remain valid.
  • Daylight Saving Time is NOT handled by the LOGO! RTC – the firmware does not auto-adjust. Implement DST in the LOGO! program using Weekly Timer blocks if required.
  • If the LOGO! has a LOGO! CMR2020 or CMR2040 cellular module installed, the cellular module will overwrite the RTC every hour using the cellular network time. This is desirable behavior but means any HMI write will be overwritten within 60 minutes.
  • LOGO! BM (basic module without Ethernet) cannot be read by a KINCO HMI – the S7-200 TCP driver requires Ethernet connectivity.
  • Do not map VB994 using the KINCO driver VD994 (32-bit) – the LOGO! firmware updates the two RTC bytes asynchronously, and a 32-bit read may capture a mid-update mismatch showing 23:90.

Summary of Address-to-Component Mapping

LOGO! VM Address KINCO Component Address Format Min Max Read/Write
VW985 (Year/Month int) VW985 Decimal 0 9999 Read-only safe
VW987 (Day/Hour int) VW987 Decimal 0 3123 Read-only safe
VW989 (Min/Sec int) VW989 Decimal 0 5959 Read-only safe
VW992 (Month/Day BCD) VW992 Hex 0 4657 Disable input!
VW994 (Hour/Min BCD) VW994 Hex 0 9065 Disable input!
VW996 (Sec BCD) VW996 Hex 0 89 Disable input!
VW998 (Day of week int) VW998 Decimal 1 7 Read-only safe

References in Procedure

Which VM addresses store the LOGO! 8 real-time clock?

The LOGO! 8 exposes the RTC in two parallel blocks: VB985–VB990 and VB998 are integer-encoded (year, month, day, hour, minute, second, day-of-week), while VB991–VB996 are BCD-encoded. For KINCO HMIs the most-used addresses are VW994 (hour/minute, BCD), VW996 (second, BCD), VW992 (month/day, BCD), and VW998 (day of week, integer 1–7).

Why does my LOGO! clock freeze when the KINCO screen is touched?

The KINCO Number Component is configured with Enable Input enabled. Each polling cycle the panel writes the displayed value back to the LOGO! VM area, overwriting the RTC. Open each RTC Number Component, uncheck Enable Input in Basic Attributes, and confirm the read-only icon is active.

What Numeric Data format should I use for VW994 (hour/minute)?

Use Hexadecimal, Word Length WORD, Integer Digits 2, Decimal Digits 2, Min 0, Max 9065. The 9065 upper limit corresponds to 0x2359 = 23:59 in BCD. With this format the field will display the raw BCD value such as 0x1437 for 14:37.

Which Kinco DTools driver should I select for a LOGO! 8?

Use the Siemens S7-200 (TCP/IP) driver on TCP port 102. Even though the LOGO! is a LOGO! and not an S7-200, the LOGO! 8 firmware implements the S7-200 communication subset for third-party integrations.

Can I read the LOGO! RTC without enabling the S7 protocol?

No. The VM RTC addresses are exposed only through the S7-200 TCP/IP server inside the LOGO! 8. If you enable only Modbus TCP on the LOGO! you can read the same data using Modbus function codes 03/04 against the Modbus register table, but the VM-to-Modbus mapping must be configured in LOGO! Soft Comfort under Tools → Modbus Connections.

Back to blog