Referencing Siemens FB Local Variables in TIA Portal

David Krause14 min read
SiemensTechnical ReferenceTIA Portal
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Function Blocks (FBs) in Siemens S7-300, S7-400, S7-1200, and S7-1500 controllers carry three categories of working memory: input parameters (IN, IN_OUT), output parameters (OUT), and internal variables. Internal variables are subdivided into TEMP (temporary) and STAT (static) declarations. The two behave identically at runtime with respect to read/write access from inside the FB, yet the offline programming environment (STEP 7 V5.x, TIA Portal V13 through V18) treats them very differently when an engineer attempts to find where a value was moved into a register or cross-reference a local variable.

This is the practical problem that surfaces during commissioning of a sequencing machine: a SequenceValue integer is supposed to advance 1 → 2 → 3 → 4 through the machine cycle, but a stray MOVE or := assignment has planted the wrong value into the tag. The engineer needs to locate every assignment to SequenceValue quickly, regardless of whether the tag is global in a Data Block (DB), static inside an FB instance, or passed as IN_OUT. TIA Portal offers several built-in tools, and understanding the distinction between TEMP and STAT determines which tools will work.

FB Variable Types: TEMP, STAT, IN, OUT, IN_OUT

Open any FB in the TIA Portal project tree, expand the FB node, and the Interface section exposes the parameter classes. The declaration table contains the following columns:

Class Scope Stored In Retained Cross-Referenceable
Input (IN) Caller writes, FB reads Call interface / temporary copy in L stack No Yes (read access)
Output (OUT) FB writes, caller reads Call interface / temporary copy in L stack No Yes (write access)
InOut (IN_OUT) Caller passes pointer, FB reads/writes Pointer to caller variable No Yes (full R/W)
Static (STAT) FB reads/writes Instance DB (non-optimized) or retain area (optimized) Optional via Retain column Yes (full R/W)
Temp (TEMP) FB reads/writes L stack (local data) – volatile No No
Constant (CONST) Read-only literal Compile-time constant N/A Yes (declaration only)

The L stack is the per-priority-class (OB) local data area. Each network inside the FB reads/writes a TEMP variable against the current OB's L stack frame, so a TEMP does not occupy a fixed offset inside an instance DB and the offline editor cannot anchor a symbol to a stable memory location for searching.

Why TEMP Variables Cannot Be Cross-Referenced

The offline cross-reference engine in TIA Portal builds its index from the symbol table, the global DBs, the instance DBs, and the fixed parameter classes of FB interfaces. A TEMP declaration produces a stack-relative identifier that exists only for the duration of the FB call. When the FB returns, the L stack frame is released and the next FB called by the same priority class reuses the same offsets. The cross-reference table therefore lists zero access points for any TEMP tag, even if it is assigned one hundred times inside the FB body.

Consequence: a search request of "where is #LocalCounter written" returns the FB declaration row and nothing else if the variable is declared TEMP. Engineers migrating from ladder or FBD, where intermediate results often live in the L stack, frequently run into this gap.

Promoting TEMP to STAT for Searchability

If a local variable is read or written in more than one network — or if an engineer must audit every write site — promote the declaration from TEMP to Static. In the FB interface editor, change the Name's Data type row, then in the Class dropdown select Static. The variable now lives inside the FB's instance DB and inherits a fixed symbol that the cross-reference engine can index.

Memory impact: Each STAT adds bytes to every instance DB that uses the FB. For multi-instance FBs, the offset is appended to the caller's instance DB layout. S7-300/400 allocate STAT in the same image as the instance DB, so a non-optimized block exposes the offset in the Offset column. S7-1200/1500 with Optimized block access hide the offset and store STAT in symbolic form only.

After changing a variable class, perform a full recompile (right-click the FB → Compile → Software (rebuild all blocks)). Without a full rebuild, instance DBs retain the old layout and the symbol will not resolve at runtime.

TIA Portal Cross-Reference Tools

Three navigation tools in the editor are relevant to the problem of "find where a tag is moved":

Tool Shortcut Function Works on TEMP?
Go to Location Ctrl + Alt + Q Lists every access to the tag at the cursor; click jumps to network No
Cross-Reference List Ctrl + Shift + F (or right-click → Cross-references) Tabular view across the entire program: access type, block, network, address, path No
Find and Replace Ctrl + F Plain-text search through the open block editor Yes (text match only)

Go to Location (Ctrl + Alt + Q)

Place the cursor on the symbol of interest and press Ctrl + Alt + Q. The Go to dialog appears with a list of every location where the tag is read, written, or both. The Access column distinguishes Read, Write, and Read/Write. Double-click an entry to jump to the corresponding network in the calling block. The shortcut is also bound to Go to in the context menu (right-click the tag).

Field use: place the cursor on "SequenceValue" in the FB and trigger Ctrl + Alt + Q. The list shows every MOVE that loads the tag, ordered by block and network. A stray 10 literal at network 47 in OB1 will appear in the list and the engineer navigates to it directly, eliminating the manual scroll line by line approach described in the original problem.

Cross-Reference List (Ctrl + Shift + F)

The Cross-Reference List is a project-wide counterpart. Right-click any tag in the editor and select Cross-references (or open Project tree → Program blocks → Show cross-references). The table that opens contains the following columns: Name, Access, Address, Type, Block, Network / Line, Path, and Comment. Filter by Access = Write to isolate all assignment sites. The list can be exported to CSV via the toolbar Export button.

Block consistency prerequisite: Both Go to Location and the Cross-Reference List rely on the project's compile state. A yellow warning icon in the project tree indicates uncompiled changes; right-click the PLC folder and choose Compile → Software (rebuild all blocks) before searching. Stale index data is the most common reason a known assignment is missing from the list.

Find and Replace (Ctrl + F)

The plain-text search operates on the open block's source. It does find TEMP symbols, because it scans the textual representation of the network rather than the symbol index. The limitation is that it returns matches inside comments, constants, and any string that contains the substring. Use Match whole word only and Match case in the search toolbar to reduce false positives. Ctrl + H opens Replace, which is useful for renaming a TEMP to a STAT declaration and propagating the change across the FB body.

The Sequence Register Pattern

The original question describes a numeric sequence register advanced by a MOVE block (Siemens S7 V5.x) or an assignment (TIA Portal SCL). The pattern is standard in discrete sequencing: each step transition writes the next integer into the register, and the register value selects the next state. A bug in the sequence — a wrong literal in a MOVE input — produces chaotic sequencing, and locating that literal efficiently is the engineer's primary concern.

Recommended implementation in TIA Portal SCL for a STEP-based sequencer:

// FB_Sequencer — interface
VAR
    SequenceValue : INT;      // STAT, retain = false
    StepComplete  : BOOL;     // STAT
END_VAR

BEGIN
    IF StepComplete THEN
        CASE SequenceValue OF
            1 : SequenceValue := 2;   // step 1 done
            2 : SequenceValue := 3;   // step 2 done
            3 : SequenceValue := 4;   // step 3 done
            4 : SequenceValue := 5;
            5 : SequenceValue := 0;   // cycle complete, reset
        END_CASE;
        StepComplete := FALSE;
    END_IF;
END_FUNCTION_BLOCK

Because SequenceValue is declared Static, every assignment above is indexed. Press Ctrl + Alt + Q on SequenceValue to enumerate all five write sites and any additional writes from OBs or other FBs that access the instance DB directly.

Watch Tables and Force Tables

Online debugging complements offline cross-referencing. Add a Watch table (project tree → Watch and force tables → Add new watch table) and drag the instance DB symbol onto the table. Connect online (Go online) and the Modify value column allows runtime writes for testing a specific step. Enable Monitor all (glasses icon) to log value changes with timestamps. For drives and interlocks, prefer Force tables with caution; force values override the program's writes and persist until explicitly cleared, which is dangerous on production machinery.

Best Practices for Variable Architecture

  1. Default to STAT for any local variable read or written more than once. Reserve TEMP for true intermediate results (loop indices, calculation scratchpads).
  2. Name variables with action_qualifier prefixes. Examples: SeqVal_CurrentStep, Timer_HomingDelay, Flag_AlarmActive. Prefixes group the tag in the symbol table and in cross-reference results.
  3. Configure Optimized block access deliberately. Optimized blocks hide absolute offsets and store STAT in a hash-keyed layout. S7-1500 benefits from optimization (faster access, better security), but external HMI tags must use symbolic addressing.
  4. Pin the cross-reference list as a permanent pane. TIA Portal allows docking the cross-reference list at the bottom of the editor so the engineer can see the impact of a rename in real time.
  5. Compile after every structural change. Even a comment edit can invalidate the index; never trust a cross-reference list with the warning triangle visible.
  6. Use Program info for project-wide audits. Project tree → Program info → Cross-references produces the same table as Ctrl + Shift + F but with project-wide filters: by block type, by access type, by date of last change.
  7. Avoid passing data through global MERGE blocks. Long chains of MOVE from one DB to another produce duplicated write sites that confound cross-reference audits. Use FB encapsulation with IN_OUT parameters instead.

Multi-Instance FBs and DB Layout

For S7-1500 projects with many similar subsystems (e.g., ten axis drives), use multi-instance FBs instead of separate instance DBs. The parent FB declares the child FB instance as Axle_1 : FB_AxisDrive in its Static section. The child FB's STAT variables are then nested inside the parent's instance DB at a parent-relative offset. Cross-references resolve to the parent FB's instance DB, which is acceptable for symbolic access. The legacy S7-300/400 pattern (one DB per instance) is still supported for migration but produces long DB lists in the project tree.

When the project uses Optimized block access, the cross-reference list shows the symbolic path (e.g., "Machine_DB"."AxisDrive_3"."ActualPosition). When non-optimized, the absolute address is shown alongside, e.g., DB100.DBX12.0. Both are clickable for navigation.

Software Version Considerations

TIA Portal Version Notable Cross-Reference Behavior
V13 / V14 Initial TIA Portal implementation; Go to Location limited to current block context only.
V15.0 / V15.1 Project-wide Cross-Reference List introduced with CSV export; optimized block access fully supported.
V16 Improved index performance; Program info cross-references gain Filter by access and Filter by block type.
V17 Cross-reference list integrates with Trace; STAT offsets visible even in optimized blocks when Permit access with absolute address is enabled in the DB properties.
V18 / V19 Added column Last modified and Modified by; performance improvements for projects above 5,000 blocks.

Engineers working on long-running S7-300/400 projects with STEP 7 V5.5 or V5.6 should use the Reference Data → Display tool. The Program Structure, Cross-References, and Assignment List views correspond to TIA Portal's Program info tabs. In STEP 7 V5, the keyboard shortcut is Ctrl + Alt + Q for Go to Location in LAD/FBD/ST editors.

Verification

After applying the techniques above, run the following checks to confirm the search infrastructure is functioning:

  1. Index validity: The project tree shows no yellow warning icons on PLC or block folders. Right-click → Compile → Software (rebuild all blocks) returns without errors.
  2. Known assignment test: Insert a MOVE 9999 → "SequenceValue" in a test network. Press Ctrl + Alt + Q on SequenceValue and confirm the new write site appears in the list.
  3. TEMP blindness confirmation: Add a TEMP variable TestTemp : INT, assign it in three networks, and run the cross-reference list. The result must show only the declaration row, confirming the platform's behavior and the need to promote to STAT for full auditability.
  4. Online monitoring: Connect online, open the Watch table, and confirm SequenceValue advances monotonically through the cycle with no skips or back-steps. If a skip occurs, the cross-reference list provides the offending network.
  5. Optimized vs non-optimized: Toggle the FB's Optimized block access checkbox, recompile, and verify the cross-reference list still shows the tag at the same symbolic path. The absolute address column disappears for optimized blocks; this is expected.

Troubleshooting Matrix

Symptom Likely Cause Resolution
Cross-reference list shows no write sites for a local variable Variable declared TEMP Promote to STAT, recompile
Ctrl + Alt + Q does nothing Cursor is in a comment or in a string literal Click on the symbol identifier (not a literal)
List misses a known assignment Project not compiled since last edit Right-click PLC → Compile → Software (rebuild all blocks)
Symbol shows red squiggle in editor Instance DB not regenerated after interface change Right-click FB → Compile, then right-click instance DB → Compile
Watch table shows Invalid value Optimized block access with absolute addressing Use symbolic tag, not DB100.DBW0
Force table value reverts immediately Program writes to the tag in a faster OB Move logic to a slower OB or remove the force
Find & Replace renames a comment string Match whole word only disabled Enable Match whole word only in the search toolbar

Field-Proven Caveats

Two production traps surface repeatedly when commissioning Siemens machines with sequence registers:

  • OB1 vs OB35 priority-class overlap. If a fast OB (e.g., OB35 cyclic interrupt at 100 ms) writes the sequence value and the slow OB1 also writes it, the offline cross-reference list shows both sites but the online trace reveals which wins. The fix is to designate a single owner OB for the sequence register; reference the cross-reference list filtered by Block = OB35 and Block = OB1 to confirm the audit.
  • Optimized block access disabled on migration. When an S7-300 project is migrated to S7-1500, TIA Portal may default the new CPU's FBs to non-optimized for backward compatibility. Symbolic HMI tags and cross-references still work, but performance suffers. Enable Optimized block access on every migrated FB and instance DB, then rebuild the HMIs with symbolic tags.

Can a TEMP variable in a Siemens FB be cross-referenced in TIA Portal?

No. TEMP variables are stored on the L stack and have no fixed symbolic location for the cross-reference engine to index. Promote the declaration from TEMP to Static in the FB interface, then recompile the project so the instance DB is regenerated. After the rebuild, the cross-reference list (Ctrl + Shift + F) and Go to Location (Ctrl + Alt + Q) will enumerate every read and write site.

What is the keyboard shortcut to find every place a tag is written in TIA Portal?

Place the cursor on the tag and press Ctrl + Alt + Q to open the Go to Location dialog, which lists every access with the Access column showing Read, Write, or Read/Write. For a project-wide view, right-click the tag and select Cross-references, or press Ctrl + Shift + F. Both tools require a fully compiled project; otherwise the index is stale and known assignments will be missing.

How do I search inside a single FB for every MOVE that loads a sequence register?

Declare the sequence register as Static in the FB interface (for example SequenceValue : INT in the Static section), recompile the FB and its instance DB, then place the cursor on SequenceValue and press Ctrl + Alt + Q. The Go to Location dialog lists every MOVE or assignment, ordered by network. Double-click any entry to jump to the offending network.

Why does Find and Replace (Ctrl + F) work on TEMP but Go to Location does not?

Find and Replace is a plain-text scan of the open editor source, so it returns any textual match including TEMP symbols. Go to Location and the cross-reference list rely on the symbol index that TIA Portal builds from the project tree, instance DBs, and fixed interface declarations. Because TEMP variables have no fixed symbol location in the index, they do not appear in those navigation results.

Does promoting TEMP to STAT change the runtime behavior of my FB?

For most applications, no. STAT variables occupy memory in the instance DB and retain their value across FB calls, whereas TEMP variables are re-initialized on each call from the L stack. If your FB relies on a variable being reset to zero at the start of every call, the promotion will change behavior. In that case, explicitly initialize the STAT at the top of the FB body or keep it as TEMP and accept the absence of cross-reference auditability.

Back to blog