Resolving WinCC V6 SP3 Alarm Logging Runtime Halt on Startup

David Krause10 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Summary

On a WinCC V6 SP3 runtime station, the HMI graphics runtime loads but Alarm Logging Runtime and/or Tag Logging Runtime never reach the Running state. The startup sequence stops with the runtime window frozen, and the project never enters active operation. In many field reports the project started normally on one PC and then fails to start on a redeployed image, a virtual machine clone, or a workstation where Windows updates have been applied.

Because Alarm Logging and Tag Logging are background services (CCAlgRtService, CCLgRtService, CCRTMgrService), a halt in any one of them blocks the central CCRuntimeManager and the WinCC Explorer status indicator stays yellow or red instead of green.

Affected Environment

Item Value
SCADA software SIMATIC WinCC V6.0 + Service Pack 3
Failing component Alarm Logging Runtime, Tag Logging Runtime
Fieldbus PROFIBUS-DP via CP-5613 (PCI / PCMCIA)
PLC connectivity SIMATIC S7-200 via OPC (typically PC Access / S7-200 PC Access OPC Server)
Operating system (typical) Windows XP Professional SP2/SP3 or Windows Server 2003
Project type Single-station or client/server with PROFINET/Industrial Ethernet backbone
Note. WinCC V6 SP3 was released for Windows XP / 2003. Running it on unsupported OS builds (Vista, Windows 7 x64 without XPMode, terminal services with non-standard session IDs) is the single largest source of runtime startup halts reported to Siemens support.

Initial Triage: System Requirements and Environment

Before touching the project, capture the four hard requirements that Siemens asks for in any WinCC V6 SP3 incident. These are the same questions that surface in every Siemens support thread on a stuck Alarm Logging / Tag Logging startup:

  1. Physical RAM. Minimum 1 GB for single-station, 2 GB recommended. Less than 1 GB will let graphics runtime start but will fault the archive services.
  2. Free disk space on the project drive. At least 2 GB free on the drive that holds \WinCC\. Tag Logging archives grow; a near-full volume is the most common reason CCLgRtService stops with archive write errors and never restarts.
  3. Concurrent processes. List every other installed application: antivirus, backup agents, OPC Scout, SIMATIC Manager, SQL Server clients, second OPC DA servers. Anything that holds a handle on the project DB blocks the runtime lock.
  4. Non-Siemens software footprint. Third-party OPC tunnellers, RSLinx, LabVIEW DSC, and Wonderware I/O servers in particular are known to hijack the COM/DCOM subsystem that Alarm Logging depends on.

Capture this data first; it is the triage that decides whether you are chasing a Windows-level problem or a project-level problem.

Collecting WinCC V6 SP3 Diagnose Files

Siemens' first-line response to any WinCC runtime halt is always the diagnose fileset. The procedure is documented in SIOS entry WinCC: Which diagnose files should be provided when an error occurs? (article ID 11965771). Collect the following before changing anything in the project:

  1. Open Windows Explorer and navigate to the runtime project folder.
  2. Open the subdirectory \<ProjectName>\diagnose. If the folder is empty, Alarm Logging never even initialised.
  3. Copy the following logs into a zip with the PC name and date stamp:
    • WinCC_SStart_<ComputerName>.log and WinCC_SStart_<ComputerName>.trc
    • WinCC_<ComputerName>.log and WinCC_<ComputerName>.trc
    • AlarmLogging_<ComputerName>.log (only present when Alarm Logging has run at least once)
    • TagLogging_<ComputerName>.log
    • CCAlgRtService.txt / CCLgRtService.txt in \Siemens\WinCC\diagnose
    • OPCServer.log from \Siemens\Automation\OPC\S7-200 PC Access\log
  4. Add the Windows System and Application event logs (export to .evt).
  5. Add msinfo32.nfo from System Information.
Important. Do not reuse a project directory that has been copied across operating systems. WinCCExplorer.cfg contains absolute paths to OPC.SimaticHMI.AlarmLogging that are only valid on the original PC. A cloned image that fails to start Alarm Logging Runtime is almost always a clone of the project folder, not the PC.

Root Cause Matrix

# Symptom in Diagnose Log Root Cause Resolution Path
1 Alarm Logging: cannot create archive database Insufficient rights on archive path or DB lock from previous crash Grant Modify on \Archives, delete *.LDF orphans, restart service
2 Tag Logging: connection to SQL server failed MSSQLSERVER (WinCC) instance stopped or disabled after reboot Set SQL service to Automatic, start manually, restart WinCC Runtime
3 OPC.SimaticHMI.AlarmLogging not registered DCOM / OPC proxy stub missing or unregistered Reinstall WinCC Runtime, run regsvr32 opcproxy.dll
4 CP-5613: PROFIBUS master not initialised Driver not loaded; simatic_net set component started but service dead Restart SIMATIC NET Configuration service, re-import station configuration
5 Runtime halts in startup window with no further trace Non-Siemens OPC server holding CLSID, blocking COM enumeration Disable 3rd-party OPC, stop with opcenum /unregserver, retry
6 Alarm Logging: license invalid Authorisation removed, expired, or transferred to another PC Transfer ALG license via Automation License Manager
7 CCRTMgrService stuck in Starting Anti-virus quarantining CCRTMgr.exe Whitelist \Siemens\WinCC\bin in AV
8 S7-200 OPC: server not responding PC Access server not started before WinCC; wrong PG/PC interface assignment Set PG/PC interface to PC Access.TCPIP.Auto.1 (or PPI/PC cable), start server, then WinCC

Solution Path A: Repair the Alarm Logging / Tag Logging Services

This is the corrective path for the most common class of halt: a project that previously ran and now stops in Alarm Logging startup. Perform the steps in order; do not skip the dependency check.

  1. Close WinCC Explorer on every PC that touches the project (clients, server, redundant pair).
  2. Open Services (services.msc) and stop in this sequence:
    1. SIMATIC HMI - CCRTMgrService
    2. SIMATIC HMI - CCAlgRtService (Alarm Logging Runtime)
    3. SIMATIC HMI - CCLgRtService (Tag Logging Runtime)
    4. SIMATIC NET Configuration Service
    5. SQL Server (WinCC)
  3. Delete leftover archive locks in \<Project>\ArchiveManager\AlarmLogging and \<Project>\ArchiveManager\TagLogging. Files named *.lck from an aborted shutdown are safe to remove.
  4. Run the project rebuild: Start > SIMATIC > WinCC > Tools > Project Duplicator. Open the project, accept the rebuild of the tag and archive database. This re-creates the COM registrations under the local account.
  5. Start the services in reverse order. Confirm each reaches Started before starting the next.
  6. Start the WinCC Runtime. Alarm Logging and Tag Logging status should turn green within 30 seconds.
Warning. Never run two WinCC projects against the same \Archives root. The archive manager does not lock at folder level; it locks at the SQL DB. Two competing startups will fault one of them with a SQL -2147467259 (0x80004005) error.

Solution Path B: Profibus CP-5613 Stack Repair

When the diagnose log shows CP-5613: PROFIBUS master not initialised, the fieldbus stack, not WinCC, is at fault. The project cannot bring up Alarm Logging Runtime because the OPC server underneath the PROFIBUS channel never publishes its tags.

  1. Open Start > SIMATIC > SIMATIC NET > Configuration Console.
  2. Expand Modules > CP-5613. Confirm the diagnostic LED on the card itself is green steady; flashing or off indicates firmware corruption.
  3. Switch the mode of CP-5613 from DP-Master to No Action, click Apply, then back to DP-Master. This reloads the firmware and the bus profile.
  4. Verify PG/PC Interface is set to CP5613(Profibus) - DP Master. A common field mistake is leaving this at CP5613(Profibus) - PG/PC after a project is migrated from a programming laptop to a runtime PC.
  5. Open WinCC Explorer > Tag Management > Profibus. Right-click the channel and choose System Parameters > Unit > Check Connection. All configured slaves should turn green.
  6. Restart SIMATIC NET Configuration Service, then the WinCC runtime.

Solution Path C: OPC Channel for S7-200

WinCC V6 SP3 does not include a native S7-200 driver. The PROFIBUS / PPI traffic to the S7-200 fleet is normally routed through S7-200 PC Access as an OPC DA server. If this OPC server is not running, Alarm Logging cannot resolve any tag whose source is the S7-200 and the runtime stops at the OPC enumeration phase.

  1. Launch S7-200 PC Access as a standalone application and confirm Test Client reads each configured S7-200 without errors.
  2. In PC Access OPC Server > Settings, verify the server is set to Run as Local Server (not Run as COM/DCOM Server) when both PC Access and WinCC are on the same station.
  3. Set the service startup type to Automatic and confirm it is started before WinCC Runtime Manager. Add a startup dependency via sc config "S7-200PCAccess" depend= "RPCSS/PlugPlay" if necessary.
  4. In WinCC Explorer > Tag Management, add an OPC channel. Browse the local OPC server list, select Siemens.S7-200PCAccess.OPCServer, and confirm the tags import without red exclamation marks.
  5. Save, close WinCC Explorer, and start the runtime.

Solution Path D: Windows / DCOM Hardening After Security Updates

The single most common reason a previously healthy WinCC V6 SP3 runtime now halts is a Microsoft Windows update that reverts DCOM permissions or that disables the MSADC / OPCEnum service. Apply this checklist whenever the halt appeared immediately after a Windows patch day or a domain policy push.

  1. Open dcomcnfg > Component Services > Computers > My Computer > DCOM Config.
  2. Locate OPCEnum, SIMATIC Alarm Logging, SIMATIC Tag Logging, SIMATIC WinCC Runtime. On each: Properties > Security, ensure the account running the WinCC service has Launch and Activation = Allow.
  3. Verify Distributed Transaction Coordinator (MSDTC) service is running. Alarm Logging uses it for SQL archive writes.
  4. Re-register the OPC proxy library:
    regsvr32 /u opcproxy.dll
    regsvr32 opchda_ps.dll
    regsvr32 opcda_ps.dll
    regsvr32 opcproxy.dll
  5. Reboot, restart the SIMATIC NET stack, then start WinCC Runtime.

Verification and Commissioning Checks

After each solution path, run the following verification before returning the station to production:

  1. In WinCC Explorer, confirm the runtime indicator is solid green for Graphics, Alarm Logging, Tag Logging, and Report.
  2. Open the Alarm Control in graphics runtime and trigger a controlled fault on a connected S7-200 station. The alarm must appear within 1 s.
  3. Open the Tag Logging Runtime window and verify the archive database receives a row per second for a selected fast tag.
  4. Open CCDiagnosticsTool (Start > SIMATIC > WinCC > Tools) and run Self-Test. No red entries are acceptable.
  5. Reboot the PC twice in succession and confirm Alarm Logging and Tag Logging reach Running without manual intervention.

Preventive Maintenance

  • Take a WinCC Project Backup after every commissioning change and store it on a separate physical volume.
  • Schedule a daily restart of the runtime PC during a known production gap; on WinCC V6 SP3 the archive manager accumulates lock handles that only a clean restart releases.
  • Patch Windows on a test clone of the runtime PC first. The runtime PC must never receive automatic updates from WSUS or SCCM without a documented regression test.
  • Export the Automation License Manager archive to a network share and validate monthly that the Alarm Logging licence has not silently migrated to another station.
  • Keep the \Archives path on a fixed-letter drive; reassigning drive letters after a disk replacement is the third most common cause of archive database not found errors at startup.

Why does WinCC V6 SP3 stop in the Alarm Logging Runtime startup window without an error dialog?

The Alarm Logging Runtime writes its progress to AlarmLogging_<Computer>.log inside the project's diagnose folder, not to a UI dialog. When the service halts, the CCRTMgrService waits for an acknowledgement that never arrives; this is why the runtime window appears frozen. Always inspect WinCC_SStart_<Computer>.trc first.

What is the minimum free disk space for WinCC V6 SP3 Alarm Logging and Tag Logging?

At least 2 GB free on the volume that hosts the project and the archive path. Tag Logging archives grow by default in 500 MB segments, and Alarm Logging rotates daily; a drive with less than 1 GB free will fault both services at startup with a SQL write error.

Can I run WinCC V6 SP3 with CP-5613 on Windows 7 64-bit?

Siemens does not certify WinCC V6 SP3 for Windows 7 64-bit. CP-5613 driver and SIMATIC NET on V6 SP3 ship 32-bit only; the only supported way to run them on Windows 7 64-bit is inside Windows XP Mode or a WinCC V7 upgrade. Field deployments of V6 SP3 on bare Windows 7 are the single most common source of intermittent runtime halts in the diagnose queue.

How do I import S7-200 tags into WinCC V6 SP3 without the project halting on Alarm Logging startup?

Install and start S7-200 PC Access as a local OPC DA server before launching WinCC. Then in WinCC Explorer add an OPC channel pointing to the Siemens.S7-200PCAccess.OPCServer CLSID. If PC Access is not running when Alarm Logging enumerates OPC servers, the project halts with OPCEnum returned 0 entries in the trace.

Which Siemens KB article lists the WinCC diagnose fileset?

Siemens SIOS entry 11965771 enumerates every diagnose file expected by support, including the location of CCAlgRtService.txt and CCLgRtService.txt. Attach the full fileset, the Windows event logs, and msinfo32.nfo when opening a support request.

Back to blog