Resolving Siemens 840D PLC Faults with STEP 7 Diagnostic Blocks
On a SINUMERIK 840D system built around an NCU 573.5 and an S7-300 CPU 317-2 DP, the operator panel (MCP / HMI) often collapses multiple underlying events into a single visible message such as Emergency Stop. The actual axis, limit-switch, or drive-side cause sits deeper in the PLC, and STEP 7's extended diagnostic instruction set is the only reliable way to expose that cause. This reference explains the alarm-routing problem, identifies the diagnostic instructions that recover the real fault, and shows how to map them to an 840D seven-axis software-limited configuration.
1. Problem Statement: Masked Alarms on the 840D HMI
A 7-axis SINUMERIK 840D sl machine running on software axis limits was reporting Emergency Stop on the operator panel during normal operation, with no clear indication of the triggering axis or PLC event. The PLC continued to run; the HMI simply displayed a generic stop. Field experience shows the following typical masking chain:
- An axis drive, encoder, or limit-monitoring event raises a boolean or word-level fault flag in the PLC user program (typically in an FC/FB chain dedicated to that axis).
- The NCK or drive-side alarm triggers an emergency-stop request bit, e.g.
M0.0or DB31..DBX6.2 (DBX6.2: Antrieb Freigabe Achse / Drive enable axisdepending on the version), which is wired to the global emergency stop. - The HMI receives the global stop bit and shows "Emergency Stop" before it has time to query the alarm history.
- The original alarm — for example, a software-limit violation, encoder error, or PROFIBUS dropout — is overwritten by a higher-priority message in the SINUMERIK alarm buffer.
The fix is to instrument the PLC with STEP 7 extended diagnostic instructions that read before the masking happens, snapshot the alarm state, and present a structured alarm list back to the MCP. Siemens documents this instruction family in the STEP 7 Safety V20 instruction collection for the safety side, and in the STEP 7 Professional / TIA Portal online help for the standard diagnostic set.
2. System Architecture and Relevant Hardware
The configuration in the source case consists of:
| Component | Designation | Role in fault path |
|---|---|---|
| CNC | SINUMERIK 840D sl | Generates NCK alarms, displays them on the HMI/MCP. |
| NCU | NCU 573.5 | Hosts NCK + PLC; provides MPI/PROFIBUS to drives and I/O. |
| PLC CPU | SIMATIC S7-300 CPU 317-2 DP (6ES7317-2AK14-0AB0 class) | Executes user program, holds alarm DBs, exposes diagnostic data. |
| Drives | SIMODRIVE 611 / SINAMICS S120 via PROFIBUS | Generate drive-side alarms that the PLC can read with SFC13 / SFC59. |
| I/O | ET 200M / ET 200S on PROFIBUS DP | Channel-level diagnostics available via GET_DIAG. |
| HMI | PCU 50 / OP 010 / MCP | Receives alarm numbers; displays masked or detailed text. |
The CPU 317-2 DP exposes four key SFCs that are still the workhorses for diagnostic retrieval in legacy STEP 7 V5.x and continue to be supported in TIA Portal through the same instruction names:
| Block | Function | Typical use |
|---|---|---|
SFC 13 / DPNRM_DG
|
Read PROFIBUS DP slave diagnostic data (up to 244 bytes) | Read slave diagnostics directly into a PLC DB. |
SFC 51 / RDSYSST
|
Read system state list SSL (partial lists 0, 1, 4, 5, 6, 7, 8, 9, 12, 13...) | Module status, CPU status, diagnostic buffer snapshot. |
SFC 59 / RD_REC
|
Read data record from a module | Channel-level diagnostics, parameter records. |
SFC 52 / WR_USMSG
|
Write a user-defined diagnostic / alarm message to the diagnostic buffer | Push a custom alarm into the buffer at the moment of the event. |
For a 7-axis machine these four SFCs — supplemented by the modern extended instructions below — are sufficient to reconstruct the full alarm history that the SINUMERIK HMI is dropping.
3. Root Cause: Why the HMI Shows "Emergency Stop" Instead of the Real Fault
Three mechanisms, in combination, are responsible for masked alarms:
- Alarm priority and overwrite in the SINUMERIK alarm buffer. The HMI alarm buffer is a ring of fixed length. A higher-priority alarm (Emergency Stop is near the top of the SINUMERIK alarm priority list — alarm class Alarm with clear and stop) overwrites the original alarm because the original was not acknowledged in time.
-
Single-bit emergency-stop chain in the PLC user program. Most standard machine tool templates wire all axis faults, drive faults, and safety faults to one OR-gated bit. When that bit trips, the HMI shows only its source. The original axis DB variable (e.g.
DB31.DBX6.2orDB31.DBX6.5) is still set, but the HMI is not reading the per-axis DBs because the global message has higher priority. - Loss of the moment-of-event context. Software-limit violations, encoder error counters, and PROFIBUS retries are transient. If the PLC does not latch them at the rising edge of the fault bit, the information is gone before the HMI refreshes the alarm page.
Any fix must therefore do three things: (a) latch the per-axis fault state at the rising edge, (b) push the captured event into the PLC's own diagnostic buffer with WR_USMSG (SFC 52), and (c) expose a structured alarm list to the HMI via a request from the MCP. The extended diagnostic instructions in STEP 7 implement (b) and (c) in a maintainable way.
4. The Extended Diagnostic Instruction Set
4.1 Alarming instructions
| Instruction | Used for | Key inputs / outputs |
|---|---|---|
Program_Alarm |
Generate a programmed alarm from a boolean trigger. The alarm text is held in the program as a multi-language text list and is displayed on the HMI. |
SIG: trigger bit, ID: alarm number, EV_ID: event ID, optional SD_1..SD_4: up to four associated values (e.g. axis index, axis position, current value of a word tag). |
Get_AlarmState |
Return the current state of an alarm — whether it is active, acknowledged, or gone. |
AlarmID, EV_ID, State (output: 0=inactive, 1=active, 2=acknowledged, 3=inactive but not yet acknowledged). |
Gen_UsrtMsg (SFC 52 / WR_USMSG) |
Write a free-form user message into the CPU's diagnostic buffer at runtime, with a timestamp, an event class, and a text ID. | SFC52(REQ:=TRUE, EV_CLASS:=B#16#9, EV_NUM:=<W#16#0001>, PRIORITY:=B#16#9, ASCII_TEXT:=...) |
AcknowledgeAlarms |
Bulk-acknowledge alarms of a defined class and source. | Used in the HMI reset FB. |
4.2 Diagnostics instructions
| Instruction | Used for | Key inputs / outputs |
|---|---|---|
DeviceStates |
Read the operating state of all stations of a DP master system or IO controller — 0 = not available, 1 = OK, 2 = maintenance required, 3 = maintenance demanded, 4 = error, 5 = cannot be evaluated. |
MODE (1 = IO device list, 2 = module list), LADDR (PROFINET IO system ID), RET_VAL, STATE (array of bytes indexed by slot). |
ModuleStates |
Read the state of modules/submodules inside a station or module. |
MODE (1/2/3/4), LADDR, output array of bytes indicating channel/group status. |
GET_DIAG |
Read the full diagnostic record of a module — current status, channel diagnostics, manufacturer-specific diagnostics, and extended text references. |
MODE (0=OK state, 1=current diagnostics, 2=statistics...), LADDR (HW identifier or diagnostic address), CHANNEL, ALL_INFO, output DiagInfo (struct). |
FDBACK (safety) |
Feedback-circuit monitoring for safety devices; DIAG output exposes non-fail-safe service information. See the FDBACK instruction reference for the DIAG byte layout. |
Used in the safety program; not for standard diagnostic tracing, but useful for emergency-stop chain validation. |
5. Implementing the Fix — Step by Step
The following procedure uses STEP 7 V5.5 + S7-300 CPU 317-2 DP. The same blocks are available in TIA Portal V16 through V20 with identical names and slightly extended parameter lists.
5.1 Prerequisites
- STEP 7 V5.5 SP4 or later, or TIA Portal V16+ with the S7-300 CPU 317-2 DP HSP.
- Hardware configuration uploaded from the NCU 573.5 (MPI/PROFIBUS, station addresses, slot assignments).
- Online connection to the CPU via TCP/IP routing through the NCU or direct MPI.
- Read-only access to the existing alarm DBs (typically
DB80..DB89for axis messages,DB2for the HMI status, and a project-specific alarm DBDB200in many standard templates).
5.2 Latch the per-axis fault at the rising edge
Insert the following logic in the axis FC (e.g. FC 100 for axis 1, FC 110 for axis 2, ... FC 160 for axis 7). The same block pattern is repeated for all 7 axes. Software-limit faults are typically DB31.DBX12.7 (positive) and DB31.DBX12.6 (negative) in the SINUMERIK axis interface, or the equivalent bits in your machine template.
// Axis 1 — software limit positive edge latch
// DB31 = axis-1 interface DB, DBX12.7 = SW-limit+
// DB100 = custom alarm-latching DB (one byte per axis)
//
A DB31.DBX12.7 // SW limit + active
FP M 100.0 // one-shot pulse on rising edge
S DB100.DBX0.0 // latch the "axis 1 SW limit" event bit
A DB31.DBX12.6 // SW limit –
FP M 100.1
S DB100.DBX0.1 // latch the "axis 1 SW limit–" event bit
Replace DB100 with a project-specific alarm-latch DB. The 8 bits per axis (one byte) are sufficient for a typical set: SW-limit+, SW-limit–, encoder error, drive communication error, position lag, follow-up error, monitoring error, controller enable missing.
5.3 Push the captured event into the diagnostic buffer with Gen_UsrtMsg
For each latched event, call SFC 52 in the same FC cycle (OB1 or OB35, depending on your template). The text ID is a free-form 12-byte ASCII, and the associated value carries the axis index and current position.
CALL SFC 52 (
REQ := DB100.DBX0.0, // request bit = latched event
EV_CLASS := B#16#9, // 9 = user-defined message, going
EV_NUM := W#16#0001, // event number, increment per event
PRIORITY := B#16#9, // priority 9 (informational)
ASCII_TEXT := 'AX1 SW + ',
EV_T := B#16#0, // not used for ASCII_TEXT
ASCII_FMT := ' ',
SCAN_FMT := ' ',
RET_VAL := MW 200
);
Once the message is in the diagnostic buffer, you can read it from STEP 7 via CPU → Online & Diagnostics → Diagnostic Buffer even if the HMI has already overwritten its own alarm page.
5.4 Build a structured alarm page with Get_AlarmState
For a polled display on the HMI/MCP, call Get_AlarmState once per OB1 cycle for each defined EV_ID. The result populates a 16-byte alarm-state record that the HMI can read via a DB and render as a list.
// Loop over 7 axes * 8 fault slots
FOR i := 1 TO 56 DO
// Get_AlarmState parameters
Get_AlarmState(
SIG := DB_Alarm[i].trigger, // i-th latched bit
EV_ID := DB_Alarm[i].EV_ID, // unique event ID assigned at compile time
State := DB_Alarm[i].state, // 0..3
TimeStamp := DB_Alarm[i].ts,
SD_1 := DB_Alarm[i].axis_index,
SD_2 := DB_Alarm[i].axis_position
);
END_FOR;
The associated values SD_1 and SD_2 are visible to the HMI in the alarm row and let the operator see Axis 3 — SW limit + at X = 142.356 mm instead of a generic stop.
5.5 Module-level diagnostics with GET_DIAG and DeviceStates
For PROFIBUS DP drops and ET 200M channel errors, use GET_DIAG in OB82 (diagnostic interrupt) and OB86 (rack failure). The interrupt OB fires the moment a station goes bad, and the call captures the failing slot and channel in a single shot.
// In OB82 (diagnostic interrupt OB)
OB82_FLT_T := OB82_FLT; // OB82 header info, indicates "module fault"
// For each slave address, call:
GET_DIAG(
MODE := 1, // current diagnostic state
LADDR := 256, // HW identifier of the station, e.g. ET 200M slave 4
RET_VAL := MW 300,
DIAG := DB_DIAG[i].record
);
To enumerate which station failed, call DeviceStates in OB86. Its STATE output array is indexed by station number; a value of 4 (error) or 5 (cannot be evaluated) flags the failing device. This is the only way to get a quick "which ET 200 dropped" indicator without manually scanning DPNRM_DG for each slave.
6. Mapping PLC Diagnostics to the SINUMERIK MCP Display
SINUMERIK HMI alarm numbers are mapped to PLC events through the following structures:
| SINUMERIK alarm number range | Source | PLC address space |
|---|---|---|
| 400000..409999 | General PLC alarms (set/reset by PLC user program) | DB2.DBX0.0..DBX24.7 (25-word bitmap) in standard templates. |
| 410000..419999 | Axis / spindle alarms from PLC | DB31..DBX36.0..DBX36.7 for spindle, DB31..DBX36.0..DBX36.7 also for axis error bits per axis. |
| 510000..519999 | Channel alarms | DB21..DBX36.0..DBX36.7 (per channel). |
| 600000..609999 | Cycle / OEM alarms | Variable — usually DB1800..DB1899 in tool-management templates. |
If your machine template uses an older alarm convention, the same conceptual mapping applies but with different DB numbers. The fix is unchanged: instrument the per-axis FC, latch the fault, and call Gen_UsrtMsg at the rising edge so the event is preserved in the CPU's diagnostic buffer.
7. Axis-Specific Diagnostics for a 7-Axis Software-Limited Setup
For a 7-axis machine (typical: X, Y, Z, A, B, C, plus a parallel axis or a sub-spindle), the software limits are stored in the NCK's machine data MD36100..MD36130 and are checked on the NC side. The PLC mirror of "software limit reached" is typically:
| Axis | DB | SW-limit+ bit | SW-limit– bit | Position-fine / coarse |
|---|---|---|---|---|
| 1 (X) | DB31 | DBX12.7 | DBX12.6 | DBD0 (position), DBD4 (actual position) |
| 2 (Y) | DB32 | DBX12.7 | DBX12.6 | DBD0, DBD4 |
| 3 (Z) | DB33 | DBX12.7 | DBX12.6 | DBD0, DBD4 |
| 4 (A) | DB34 | DBX12.7 | DBX12.6 | DBD0, DBD4 |
| 5 (B) | DB35 | DBX12.7 | DBX12.6 | DBD0, DBD4 |
| 6 (C) | DB36 | DBX12.7 | DBX12.6 | DBD0, DBD4 |
| 7 (aux) | DB37 | DBX12.7 | DBX12.6 | DBD0, DBD4 |
The emergency-stop chain is usually a single bit, e.g. DB10.DBX56.1 (E-Stop group) in the standard FSDB. The PLC often ORs all per-axis fault bits into this single bit. The original fault is invisible from the HMI exactly because of this OR-collapse. Decoupling is straightforward: instead of OR-ing the bits directly, OR them and latch them into a separate DB before passing the group bit on to the FSDB.
8. Verification: Proving the Fix Works
-
Static verification in STEP 7. Open Program → Compile All. The Program_Alarm blocks must compile without warnings. The
EV_IDvalues must be unique across the whole program (Siemens allocates them from a single global pool; collisions produce a download error). -
Online diagnostic buffer check. Trigger a deliberate software-limit violation on a single axis by setting a low MD36100 value via Commissioning → Axes → Software Limits. The diagnostic buffer should show a user message like
AX3 SW+within 100 ms of the violation. Open CPU → Online & Diagnostics → Diagnostic Buffer and confirm timestamp and event number. -
Alarm-state polling on the HMI. From the MCP, open the alarm page, select "Detail view" if available. The active alarm row should now display the axis index and the position value, e.g.
Axis 3 — SW+ at X = 142.356 mm. -
PROFIBUS dropout simulation. With
DeviceStatesrunning, unplug a PROFIBUS connector from one ET 200 station. The OB86 must fire,DeviceStatesmust report state 4 for that slot, and the HMI must show a station-level diagnostic alarm rather than a generic Emergency Stop. -
CPU restart test. Power-cycle the NCU. After restart, the latched alarm bits in
DB100will be cleared (volatile), but the diagnostic buffer entries from SFC 52 will persist until overwritten. Confirm the buffer is queryable after a cold restart.
9. Fault Code Reference Table
Commonly observed causes of "mystery" Emergency Stop on an 840D / 317-2 DP system, and where to look in STEP 7:
| Symptom | Likely source | PLC tag / DB | Diagnostic instruction to use |
|---|---|---|---|
| Emergency Stop with no prior alarm | Axis software limit tripped | DB31..DB37.DBX12.6/7 | Gen_UsrtMsg at the rising edge + Get_AlarmState |
| Emergency Stop after a brief axis movement | Position lag or follow-up error | DB31..DBX11.4 (Follow-up), DB31..DBX11.5 (Coarse pos), DB31..DBX11.6 (Fine pos) | Gen_UsrtMsg with associated value = lag distance |
| Emergency Stop during a tool change | Spindle / tool clamp limit switch | DB31.DBX83.x family, or project-specific | Program_Alarm on the limit switch, with associated value = tool number |
| Emergency Stop at program start | PROFIBUS slave not in run state | I/O diagnostic address of the slave | DeviceStates + GET_DIAG in OB82/OB86 |
| Emergency Stop after enabling drives | Drive-side fault on SINAMICS S120 | DP slave address of the drive, fault word via standard telegram 1/2 | SFC 13 DPNRM_DG to read full diagnostic buffer, or RD_REC on record index 947/950 |
| Emergency Stop on safety circuit open | Failsafe input or feedback circuit | F-DB F-DI status, FDBACK.DIAG byte |
FDBACK instruction DIAG output, see FDBACK documentation |
10. Field-Proven Caveats and Edge Cases
-
OB35 scan time vs. SFC 52 throughput. Calling
WR_USMSGin OB1 at 10 ms cycle with many latched events can saturate the diagnostic buffer. Keep event calls in OB35 (default 20 ms) and only call on the rising edge. -
Event ID uniqueness. Every
Program_AlarmandGen_UsrtMsgcall needs a uniqueEV_ID/EV_NUMwithin the program. STEP 7 enforces this at download; pre-allocate a header file or a tag table to track. -
Get_AlarmState timing. An alarm that is active for fewer than two OB1 cycles can be missed. To avoid this, latch the trigger bit (FP/edge) and call
Get_AlarmStateon the latched bit instead of the raw input. - CPU 317-2 DP performance headroom. The CPU 317-2 DP has a bit-test time of 18 ns. Adding 7 axes × 8 events × 4 instructions per event per OB35 cycle costs roughly 0.4 ms — well within the 20 ms OB35 budget. For OB1 at 5 ms, the headroom shrinks to 0.1 ms; consider moving heavy calls to OB35.
-
Multilingual alarm text.
Program_Alarmsupports project-level text lists for EN, DE, FR, etc. These text lists must be present in both the STEP 7 project and the HMI project; mismatches produce the error "Alarm text not found". -
Migration to TIA Portal. The instruction names are identical in TIA Portal V13+. The FB / FC names for the axis routines may differ between templates (e.g.
AXIS_LIM_CHECKin some standard toolkits,FC 100in others). Verify the actual FC name in your project before doing a bulk search-and-replace.
11. Diagnostic Workflow Summary
- Confirm the masking chain: per-axis DB bit → OR-gate → global E-Stop bit → HMI alarm page.
- Add rising-edge latches in the per-axis FC for every fault bit you want to preserve.
- Call
Gen_UsrtMsg(SFC 52) at the rising edge to write a timestamped event into the CPU's diagnostic buffer. - Replace the OR-gate with a latch-and-OR; keep the original event bits visible in a separate alarm DB.
- Build a polled alarm-list FB using
Get_AlarmState; expose the result to the HMI as a structured list with associated values. - For PROFIBUS drops, wire
DeviceStatesandGET_DIAGin OB86 and OB82. - For safety-circuit events, monitor the
FDBACKinstructionDIAGoutput as documented in the STEP 7 Safety V20 manual. - Verify by deliberately forcing a software limit and checking the diagnostic buffer online.
12. FAQ
Which STEP 7 instruction is most useful for tracing a masked Emergency Stop alarm on a SINUMERIK 840D?
Gen_UsrtMsg (SFC 52 / WR_USMSG) is the workhorse: call it at the rising edge of every per-axis fault bit so the event lands in the CPU's diagnostic buffer with a timestamp. The HMI can no longer mask it because the CPU buffer is independent of the SINUMERIK alarm buffer.
Why does the HMI show Emergency Stop instead of the original axis fault?
The PLC user program ORs all per-axis fault bits into one global E-Stop bit, and the SINUMERIK HMI alarm buffer gives Emergency Stop a higher priority than the original axis message. The original event is overwritten before the operator sees it. Latch the per-axis bits and call Gen_UsrtMsg at the rising edge to preserve the cause.
How do I get the diagnostic buffer online in STEP 7?
Connect to the CPU 317-2 DP via TCP/IP routing through the NCU 573.5 or direct MPI. Open CPU → Online & Diagnostics → Diagnostic Buffer. The events written by Gen_UsrtMsg appear there with their ASCII text and timestamp; the buffer is preserved across power cycles and is the first place to look when the HMI alarm page is unhelpful.
Where do software-limit faults appear in the PLC interface DB for an 840D axis?
For a 7-axis machine, axis 1..7 use DB31..DB37 respectively. The positive software-limit bit is DB3x.DBX12.7 and the negative software-limit bit is DB3x.DBX12.6 in the standard SINUMERIK PLC interface. Position actual value is DB3x.DBD0.
Do I need STEP 7 V5.5 or TIA Portal for these diagnostic instructions?
Both. The SFCs 13, 51, 52, and 59 exist in STEP 7 V5.5. TIA Portal V13+ uses the same instruction names (Program_Alarm, Get_AlarmState, Gen_UsrtMsg, DeviceStates, ModuleStates, GET_DIAG) with extended parameter sets. For a CPU 317-2 DP running an 840D, the legacy SFCs in V5.5 are still fully supported in TIA Portal V16+ through the Legacy instruction category.