Resolving Siemens LOGO! Analog Jumps from VM Address Overlap

David Krause19 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

A Siemens LOGO! 8 base module (catalog 6ED1052-1MD08-0BA1 for the 12/24 VDC variant, or 6ED1052-1FB08-0BA1 for the 230 VAC variant, firmware 0BA8 ES 09 or newer) is reading a duct temperature sensor wired for 4-20 mA through a LOGO! AM2 analog expansion (6ED1055-1MA00-0BA2). The scaled value enters an Analog Amplifier / Threshold block (B006) configured to a range of -25 to +50 °C. The output of the amplifier is published to a SIMATIC KTP700 Basic panel (6AV2 123-2GB03-0AX0) over PROFINET for operator visibility. The program documentation follows the conventions in the LOGO! 8 System Manual.

For the first hour of operation, the temperature displayed on the HMI sits steady at approximately 20 °C, and the run output is healthy. After roughly 60 minutes the HMI field abruptly renders "####" and the program stops driving the fan as if the operator had pressed the hard-wired stop pushbutton. The behavior is fully repeatable from a cold start.

The "jump" is not caused by the sensor, the transmitter loop, or the AM2 expansion. The fault is a classic case of variable-memory (VM) address aliasing: a 16-bit Word tag used to publish the temperature to the HMI shares its 16 bits with two discrete Bit tags that drive the start and stop logic. Each refresh of the temperature word silently clears or sets those bits.

Symptom summary: A Word value that has been stable for an hour suddenly overwrites unrelated bit markers. The HMI field renders "####" because the integer value has crossed the 4-digit format ceiling (or the signed 16-bit boundary), and the LOGO! drops the run output because the "run" enable bit was cleared by the same word write. The same class of failure – an analog value appearing to "jump" into a digital region – is also documented in the Rockwell Automation knowledge base for ControlLogix analog modules.

Affected Hardware, Modules, and Firmware

Component Catalog / Article Number Role in the Fault
LOGO! 8 base module, 12/24 VDC, display 6ED1052-1MD08-0BA1 Hosts the LSC program, the four onboard 0-10 V analog inputs, and the network interface to the HMI.
LOGO! 8 base module, 230 VAC, display 6ED1052-1FB08-0BA1 Alternate catalog; identical VM map and programming rules.
LOGO! AM2 analog input expansion 6ED1055-1MA00-0BA2 Two analog inputs, each software-selectable 0-10 V or 0/4-20 mA; resolution 11 bits + sign. See the AM2 / AM2 RTD manual.
LOGO! AM2 RTD expansion 6ED1055-1MD00-0BA2 Two Pt100 / Pt1000 inputs; cannot accept a 4-20 mA loop-powered transmitter.
LOGO! TDE text display 6ED1055-4MH08-0BA1 Optional external display; uses the same VM map as the base module.
KTP700 Basic PN, 7" TFT, 800 x 480 6AV2 123-2GB03-0AX0 Renders the temperature; binding to the wrong VM Word is the source of the "####" overflow. See the KTP700 Basic operating instructions.
LOGO! Soft Comfort, programming suite 6ED1058-0BA08-0YA1 (DVD) – V8.4 minimum Source-level editor; the only tool that displays the full VM address map (Tools > Address Overview, F2). Download: LOGO! Soft Comfort V8.4.
Firmware on the base module 0BA8 ES 09 (FS 09) or later Required for AM2 expansion auto-discovery; older firmware rejects the AM2 silently and the inputs read 0.

Root Cause – VM Address Aliasing in the LOGO! 8

The LOGO! 8 exposes a single byte-addressed Variable Memory (VM) area. LOGO! Soft Comfort allows the same physical bytes to be referenced as Bit (Vb.s), Byte (VBn), Word (VWn), or Double Word (VDn) depending on how the tag is declared at the block I/O. The mapping is fixed at the silicon level:

  • Bit tag Vb.s occupies bit s of byte b
  • Byte tag VBn occupies byte n
  • Word tag VWn occupies bytes n and n+1 (low byte at n, high byte at n+1, little-endian)
  • DWord tag VDn occupies bytes n through n+3 (least significant byte at n)

LOGO! Soft Comfort does not enforce protection against overlapping these references. A bit at V1.2 and a Word at VW1 reference exactly the same physical byte (byte 1) in two different ways. The same aliasing hazard is called out in the Siemens LOGO! 8 System Manual memory-layout chapter.

Siemens publishes a recommended address map for the LOGO! 8 that places the variable types in non-overlapping regions:

Address Range Type Recommended Use Capacity
V0.0 – V9.7 Bit (10 bytes) Digital markers, start/stop latches, mode bits, alarms 80 bits
VB10 – VB39 Byte (20 bytes) Byte-wide I/O, handshakes, status words, raw scaling 20 bytes
VW40 – VW198 Word (160 bytes, 80 words) Scaled analog values, setpoints, counters, HMI tags 80 words
VD200 – VD296 DWord (100 bytes, 25 DWords) 32-bit counters, long IDs, packed bitfields, time tags 25 DWords

The failing program placed the scaled temperature on VW1, an address inside the bit region. VW1 occupies byte 1 (which holds V1.0 through V1.7) and byte 2 (which holds V2.0 through V2.7). The operator start input was declared as V1.2 and the stop input as V1.4. On every scan the LOGO! re-evaluated the amplifier B006 and wrote the new scaled integer back to VW1. A value of 20 (0x0014) places 0x14 in byte 1 – a bit pattern of 0001 0100 – leaving V1.2 clear and V1.4 set. Once the temperature integer crossed certain thresholds, the high or low byte of the new value cleared the run-enable bit, latched the run output off, and the fan stopped.

Key insight: The "jump" is a deterministic bit-flip caused by the program writing a 16-bit word into an address range that is supposed to be used only for individual bits. It is not an electrical fault on the 4-20 mA loop, not a sensor drift issue, and not a noisy wiring problem. The same root-cause pattern is reported for CompactLogix analog modules in the Rockwell Automation knowledge base (id 1074371).

Why the HMI Shows "####"

The KTP700 Basic uses a 16-bit signed integer tag to display the scaled temperature. The configured display format reserves four digits with one decimal place. When the underlying integer exceeds the format range (or underflows the negative bound) the panel renders the field as "####" to indicate "value present, but cannot be displayed". The actual integer can still be inside the 16-bit range – the panel is rejecting it because of the operator-defined display mask, not because of overflow in the controller.

Common format mistakes that produce "####" on the KTP700 (per the KTP700 Basic manual):

  • Display format set to 999 or 9999 with a value that exceeds the format ceiling (e.g. 0x7FFF = 32767 in a 4-digit field).
  • Decimal places set to 2 when the controller produces a 16-bit integer (the integer 2014 with two decimals is rendered as "20.14" but the format reserves only one decimal place; the field shows "####" until the format is corrected).
  • Signed/unsigned mismatch: a negative value displayed in an unsigned field, or vice versa.
  • Tag length mismatch: a 32-bit tag is being read as 16-bit and the upper 16 bits are non-zero.
  • Acquisition cycle too slow: the HMI is reading the tag faster than the LOGO! updates it, and the panel substitutes "####" for "value not yet refreshed".

In this program, the format ceiling was the proximate trigger for the "####" display, but the actual machine stop was driven by the run-enable bit being cleared, not by the HMI display itself. Once the VM overlap is fixed, the format mask should be rechecked: a four-digit signed format with one decimal place, for example, accepts -999.9 to +9999.9, which is sufficient for the -25 to +50 °C working range.

Step-by-Step Resolution

  1. Open the LOGO! program in LOGO! Soft Comfort V8.4 or later and connect to the controller in online mode.
  2. Press F2 (or use Tools > Address Overview) to open the VM address map. The map lists every Bit, Byte, Word, and DWord that is currently in use.
  3. Sort the map by address. Confirm that VW1 is present and that V1.2 and V1.4 are also present – these are the colliding references.
  4. Open the schematic and identify the block (typically an Analog Amplifier, Analog Threshold, Math, or Multiplexer) that writes the scaled temperature. Click the output parameter and change it from VW1 to an unused Word address inside the recommended Word region. The smallest free Word is VW40; if that is already in use, advance to VW42, VW44, etc.
  5. Repeat step 4 for any other block that points at the bit region as a Word. Common offenders are Math blocks where the user typed a Word address in the bit region, and PI (Process Image) tags that have been re-typed as a Word.
  6. Open the KTP700 project in WinCC Basic (TIA Portal V16 or later) or the legacy WinCC flexible 2008 SP5. Locate the HMI tag that is bound to VW1 on the LOGO! connection. Re-bind it to the new Word address (e.g. VW40). Save and compile the HMI project. TIA Portal download portal: TIA Portal V16.
  7. Transfer the updated LOGO! program to the controller using Ethernet, micro SD, or the LOGO! Soft Comfort online connection.
  8. Re-download the HMI project to the KTP700 over PROFINET (or USB if PROFINET is not yet configured).
  9. Cycle power to the LOGO! base module to clear all VM bits to their power-on defaults and force the HMI to re-initialise the tag.
  10. Verify that V1.2 and V1.4 still represent the start and stop inputs, and that the scaled temperature is now read from the new Word address.

Verification Procedure

After applying the fix, exercise the system in three regimes to confirm that the bit aliases are gone and the analog value no longer "jumps" into the digital region.

  1. Cold-start test: Power down the LOGO!, wait 30 seconds, and re-apply power. Monitor the temperature on the KTP700 for at least four hours. The reading should remain stable within the resolution of the sensor (typically ±0.5 °C for a Pt1000 transmitter, ±0.2 °C for a high-grade 4-20 mA unit).
  2. Setpoint step test: From the HMI, drive the setpoint from 20 °C to 5 °C and back to 20 °C. Confirm that the heating/cooling output toggles correctly and that the run output never drops out.
  3. Bit integrity scan: In LOGO! Soft Comfort, open Tools > Online Test and observe V1.0, V1.2, V1.4, and the new temperature word simultaneously. The bits should be stable regardless of the temperature value, and the word should track the analog input.
  4. Watchdog soak test: Run the system for a full 24 hours. Log the HMI value to a USB stick via the LOGO! data-log feature (Project > Data Log). Inspect the log; the temperature trace should be smooth and continuous with no discontinuities greater than the sensor's specified noise floor.
  5. Boundary sweep: Force the analog input to its full-scale span by injecting 4 mA and 20 mA with a calibrated current source. Confirm that the word on the HMI reads the expected scaled value (e.g. -25 at 4 mA, +50 at 20 mA) and that the bits V1.x do not change.
  6. Polarity reversal test: Reverse the polarity of the AM2 input leads; the controller should drive the value to the under-range limit (typically -32768) and the HMI field should render "####" without disturbing V1.x. This proves the loop is the only path by which the value can change.

Signal Integrity Checks for 4-20 mA Loops

Even after the VM fix, a properly engineered loop should be checked for noise, ground loops, and shielding problems. Symptoms of a marginal 4-20 mA loop are similar to the VM aliasing symptom (value appears to "jump"), so the loop must be validated independently of the controller fix.

Check Method Acceptance
Loop voltage at the transmitter terminals Measure DC voltage at the AM2 input screw terminals with the transmitter connected and the loop powered. ≥ 11 VDC at 20 mA for a typical 2-wire loop-powered transmitter; below 10 V indicates loop resistance too high or supply insufficient.
Loop resistance (transmitter + cable) Disconnect the transmitter, short the AM2 input, and measure loop resistance with an ohmmeter; or use a loop calibrator in resistance mode. 250 Ω typical; total loop resistance must be lower than (Vsupply – 11 V) / 0.020 A.
Noise pickup on the loop Connect an oscilloscope across the AM2 input with a 250 Ω shunt; observe peak-to-peak ripple. < 1 % of span (i.e. < 0.16 mA peak-to-peak for a 4-20 mA loop) when VFDs or large contactors are active.
Shield grounding Verify the cable shield is bonded at the panel end only, not at the sensor end; check for multiple ground points on the shield. Single-point shield bond at the panel; ground loop current must be < 1 mA.
Polarity and wiring Verify + and – at the AM2 input match the transmitter; verify the AM2 DIP switch (where present on early modules) is set to "0/4-20 mA" rather than "0-10 V". Polarity and DIP switch both correct.
AM2 channel selection Confirm the program reads from the correct AM2 input (AI5 or AI6 for the first AM2, AI7 or AI8 for the second) and that the corresponding input LED on the module is active. Block input points to the correct AI.

Behaviour identical to the VM aliasing symptom can also be produced by an intermittent open circuit on the analog input. A 4-20 mA transmitter with a broken wire drives the input to its over-range value; the LOGO! then scales that to the maximum of the amplifier range, which lands in the "####" region of the HMI and may also disturb downstream logic. The diagnostic test is to inject a stable 12.00 mA from a calibrator and observe the HMI – if the HMI is stable at the scaled value, the loop is healthy. If the HMI still jumps, the loop is the problem, not the VM map.

Mathematical Block Configuration (B006)

The Analog Amplifier block (B006 in the original program) is the typical offender because it takes a raw analog value from the AM2 input and rescales it to engineering units. The block is configured with four parameters:

Parameter Symbol Value in the Failing Program Effect
Sensor type — 0-10 V or 4-20 mA (set in the AM2 DIP switch and the block's "Type" parameter) Selects the input scaling curve.
Minimum sensor value x1 0 Raw input at the bottom of the range.
Minimum output value y1 -25 Scaled value when the input is at x1 (0 V or 4 mA).
Maximum sensor value x2 1000 (raw counts) or 10 V / 20 mA Raw input at the top of the range.
Maximum output value y2 +50 Scaled value when the input is at x2.
Output destination Q VW1 (in the failing program – must be moved to VW40 or higher) VM Word that receives the scaled integer.
Gain / offset G, O Default 1.00 and 0.00 Optional second-stage scaling. y_out = G * (y_amp + O).

The block's transfer function is a straight line: y = y1 + (x - x1) × (y2 - y1) / (x2 - x1). The output is a 16-bit integer in the LOGO! 0BA8; the fractional part is truncated, not rounded. If a temperature is required to one decimal place, the block's output must be scaled in tenths of a degree (e.g. -250 to +500) and the HMI configured to show one decimal place. This is the most common source of a "0.4" / "0.5" quantization error on the KTP700.

VM Address Mapping Best Practices

The VM aliasing problem is so common that Siemens publishes explicit guidance for the LOGO! 8 series in the LOGO! 8 System Manual. Apply the following rules to every new program.

  1. Never assign a Word or DWord tag inside the bit region (bytes 0 to 9). Bits 0 to 9 are exclusively for digital flags.
  2. Never assign a Word or DWord at an odd address. LOGO! 8 silently allows odd Word references, but the resulting address straddles two words of the underlying bus and is hard to reason about. Force every Word to an even address.
  3. Never assign a DWord at an address that is not a multiple of 4. Same reasoning as above.
  4. Maintain a written VM map on paper or in a spreadsheet. The columns are: tag, address, type (Bit/Byte/Word/DWord), used by block(s), and HMI binding.
  5. If the program is networked to an HMI, give every HMI tag its own dedicated Word address; do not pack HMI tags into bytes or bits.
  6. When refactoring, use Tools > Address Overview (F2) to find any tags that violate the rules above before the program is transferred to the controller.
  7. For larger programs, request the LOGO! Soft Comfort Address Overview as a CSV (LOGOSoft V8.4 supports it via File > Export > Address Overview) and store it in the project documentation. This gives the maintenance engineer an at-a-glance map of every tag in the controller.
  8. When adding a new Word or DWord, choose the next free address in the recommended region by scanning the Address Overview – never pick an address in the bit region because the upper bytes of the range are "unused".

HMI Tag Binding in WinCC Basic / TIA Portal

The KTP700 Basic is configured in WinCC Basic (part of the TIA Portal V16 installation) or the legacy WinCC flexible 2008 SP5. Tag binding is where the analog value crosses from the controller into the panel.

  1. Open the HMI project in TIA Portal and navigate to HMI Tags > Default Tag Table.
  2. Locate the temperature tag (default name VW1 from the original program). The connection should point to the LOGO! connection (default: LOGO!_1 with a PROFINET address matching the base module).
  3. Change the address from VW1 to the new Word address (e.g. VW40). Ensure the data type remains Int (16-bit signed).
  4. Open the screen that contains the I/O field, select the field, and confirm the tag binding in the Properties pane. The format mask should be a 4-digit signed integer (e.g. 9999) and the number of decimal places should match the engineering units (typically 1 for °C).
  5. Compile the HMI project. Resolve any warnings about address mismatches before downloading.
  6. Download to the KTP700 over PROFINET; restart the panel if prompted.

A common secondary issue is that the HMI is reading the tag at the wrong polling rate. The default LOGO! polling rate is 500 ms. If the application requires sub-second display updates, the polling rate on the connection can be reduced to 100 ms in the HMI connection properties. Be aware that this increases the load on the LOGO! communication processor; do not drop below 100 ms on a base module without an AM2 communication module.

Diagnostic Workflow Summary

Step Action Tool Expected Result
1 Open the Address Overview and verify no Word/DWord lives in bytes 0-9. LOGO! Soft Comfort, F2 No overlap.
2 Confirm every Word is at an even address, every DWord at a multiple of 4. LOGO! Soft Comfort, F2 (sort by address) All Word/DWord addresses aligned.
3 Inject 12.00 mA from a calibrator into the AM2 input; observe the temperature word on the HMI. Calibrator + ammeter Stable reading; bits V1.x unchanged.
4 Bound the analog span to the HMI display mask. The amplifier output should never exceed the format ceiling of the I/O field. WinCC Basic / TIA Portal No "####" in the field.
5 Soak test the system for 24 hours and dump the data log. LOGO! data log to USB Smooth trace; no discontinuities.
6 Cross-reference the LOGO! address map to the HMI tag table. Every HMI tag should be bound to a unique Word in the recommended region. Spreadsheet or paper 1:1 correspondence, no shared addresses.
7 Force the amplifier output to its maximum (e.g. 50 °C) and to its minimum (e.g. -25 °C); confirm no V1.x bit changes. LOGO! Soft Comfort Online Test Word tracks; bits V1.x stable.

Related Field Observations

The "value jumps from a steady number to a different number" symptom is also produced by:

  • An intermittently open input on the analog channel. The LOGO! AM2 inputs default to "over-range" (32767 counts) when the input is open; this is indistinguishable from a "value above 50" condition unless the loop is tested with a calibrator.
  • Cross-talk between two analog inputs on the same AM2 module when the cable shield is missing or grounded at both ends.
  • Noise coupling from a VFD output cable that runs in parallel with the analog cable for more than 3 m. The Siemens installation guide recommends 200 mm minimum separation between analog and power cables, with metallic conduit or a screened divider for runs longer than 10 m.
  • A 24 V supply that is sagging under load (large inrush on a contactor coil) and dragging the loop voltage below the transmitter's compliance range.
  • A pinched or chafed cable where the shield is intermittently shorted to the conductor, dragging the input to a near-zero reading.
  • Two transmitters connected in parallel by mistake on the same input (the higher transmitter wins, but only when both are above 4 mA; the value "jumps" as the other transmitter takes over).

Each of these can be ruled out with a 5-minute loop test using a calibrator and a multimeter. The VM aliasing symptom is unique in that the value "jumps" only when the controller writes a new Word into the bit region, not when the analog input itself changes. If the value holds steady while the calibrator is connected and only moves with the calibrator, the VM map is the problem; if the value moves while the calibrator is held steady, the loop is the problem.

FAQ

Why does the HMI show "####" when the value is only 50?

The KTP700 Basic shows "####" when the underlying integer value cannot fit the configured I/O field format. A four-digit signed format with one decimal place, for example, accepts values from -999.9 to +9999.9; anything outside that range renders as "####". Verify the format mask and the number of decimal places in the I/O field properties in TIA Portal.

What is the correct VM address range for analog values on a LOGO! 8?

Siemens recommends Word tags in the range VW40 to VW198 and DWord tags in the range VD200 to VD296. The first 10 bytes (V0.0 to V9.7) are reserved for bit flags. Placing a Word or DWord inside the bit region is the most common cause of unexpected "jumps" or stuck output conditions.

Can I use the LOGO! onboard analog inputs for a 4-20 mA sensor?

No. The four onboard analog inputs (AI1 to AI4) on the LOGO! 8 base module are 0-10 V only. For 4-20 mA you must add an AM2 expansion (6ED1055-1MA00-0BA2) and set the AM2 DIP switch to the 0/4-20 mA position. The AM2 RTD (6ED1055-1MD00-0BA2) is for Pt100/Pt1000 sensors only and cannot accept a current-loop input.

Will changing the Word address in LOGO! Soft Comfort break the HMI tag?

Yes, until you also change the HMI tag in WinCC Basic or TIA Portal. The LOGO! and the KTP700 must agree on the new address; otherwise the HMI will show "####" or "0" depending on the address pattern. Update both projects, transfer the LOGO! program first, then download the HMI project.

How can I tell from the HMI alone whether the fault is the VM map or the analog loop?

Disconnect the field wiring at the AM2 input and inject a known 12.00 mA from a loop calibrator. If the HMI tracks the calibrator's value stably, the loop is healthy and the fault is the VM map. If the HMI still jumps or pegs, the loop is the problem (open wire, shield ground loop, or supply sag). The two faults produce identical HMI symptoms but require different fixes.

Back to blog