S7-300 SM 331 7FFF Overflow: Multi-Channel Analog Fault Diagnosis

David Krause19 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

S7-300 SM 331 (6ES7331-7KF02-0AB0) 7FFF Overflow: Multi-Channel Analog Input Fault Diagnosis

On a SIMATIC S7-300 system fitted with SM 331 analog input module 6ES7331-7KF02-0AB0, all four configured 4-20 mA channels returned 7FFFhex (decimal 32767) whenever a faulty pressure transducer was connected. The card had already been swapped for a new unit, the field wiring measured 9 mA (well inside range), and the diagnostic buffer was empty. Removing the field wiring from the suspect channel cleared the fault on the other three channels. The same fault then reproduced on a spare slot. This article explains why a single 4-20 mA channel can drive all configured channels of a 6ES7331-7KF02-0AB0 to 7FFF, how the Mana terminal interacts with the current loop, and the field procedure to isolate the fault without stopping production.

Module in scope: SIMATIC S7-300 SM 331, MLFB 6ES7331-7KF02-0AB0 (8 AI, 13-bit, isolated, with diagnostic interrupt). See the S7-300 Module Data manual for full specifications.

Module Identification: 6ES7331-7KF02-0AB0

The 6ES7331-7KF02-0AB0 is the 8-channel, 13-bit resolution variant of the SM 331 family, released as the diagnostic-capable successor to the non-diagnostic 6ES7331-7KF01-0AB0. The "-7KF02-" suffix indicates:

  • 8 analog inputs (4 differential + 4 single-ended, or 8 single-ended depending on wiring mode)
  • Resolution 13 bit + sign (12 bit + sign bipolar, 14 bit unipolar)
  • Galvanic isolation between backplane bus and process
  • Programmable per channel group (pairs of channels)
  • Hardware interrupt and diagnostic interrupt capability
  • Wire break detection on current and RTD ranges
6ES7331-7KF02-0AB0 key specifications
Parameter Value
Number of inputs 8 (4 channel groups of 2)
Resolution 13 bit + sign bipolar; 14 bit unipolar
Conversion time per channel 10 ms to 23 ms (range and mode dependent)
Operating modes Voltage +/-10 V, +/-5 V, 0-10 V, 1-5 V; Current +/-20 mA, 0-20 mA, 4-20 mA; RTD Pt100/Ni100; Thermocouple type J, K, N, R, S, T, B, E, U, L
Diagnostic Wire break, overflow, underflow, group error, parameter assignment error
Galvanic isolation Yes (process to backplane bus)
Front connector 20-pin screw (6ES7392-1AJ00-0AA0) or spring (6ES7392-1BJ00-0AA0)
Configurable in STEP 7 V5.5+ or TIA Portal V13+

The module is configured in HW Config (STEP 7) or the TIA Portal device view. The "Measuring" drop-down per channel group selects the input type; the "Diagnostics" check box enables the diagnostic interrupt (OB82). See the SIMATIC S7-300 Automation System manual for installation and parameter assignment details.

Understanding 7FFF Encoding on Siemens Analog Inputs

SM 331 modules return 16-bit integer values to the CPU. The 7FFFhex code is not a real measurement; it is the encoding for "overflow / range exceeded" generated internally by the module's ADC. The full range encoding table for the 4-20 mA input range is:

SM 331 analog value representation (4-20 mA range)
Range Encoded value (hex) Meaning
Current above 22.81 mA 7FFF Overflow
22.81 mA down to 20.001 mA 7EFF..6C01 Overrange
20 mA 6C00 Nominal full scale
20 mA down to 4 mA 6BFF..0001 Normal range
3.999 mA down to 1.185 mA 0000..7D00 (with 7FFF on some FW for wire break) Underrange / wire break
Below 1.185 mA 8000 (underflow on older FW) or 7FFF (wire break on current FW) Underflow or wire break

On a 4-20 mA channel, the module returns 7FFF whenever it detects a wire break (open current loop). This is the same code as a real overflow, so the application logic cannot distinguish them numerically; only the diagnostic interrupt (OB82) and the diagnostic buffer can tell the two apart. Refer to the SM 331 module manual for the complete encoding table and the threshold at which wire break is reported.

Important: 7FFF as a raw input value can mean (a) the signal is genuinely over range, (b) wire break on a 4-20 mA channel, or (c) a common-mode or reference fault on the Mana terminal that pulls the input stage of multiple channels into saturation. Distinguishing the three requires the diagnostic buffer plus a physical loop check.

Why Multiple Channels Read 7FFF at Once

The SM 331 6ES7331-7KF02-0AB0 multiplexes the 8 inputs into a single ADC through a front-end switch matrix. Although each input is converted sequentially, several inputs share a common analog reference (Mana) inside the module. The input stage uses a differential amplifier whose return path is the Mana terminal. If Mana is lifted, shorted, or driven by an external ground loop, every channel that uses that Mana rail can saturate at the positive rail of the input stage, and the ADC quantises that rail as 7FFF.

The 6ES7331-7KF02-0AB0 routes Mana per channel group. With the default address assignment in HW Config, channels 0-1 share Mana 0, channels 2-3 share Mana 1, channels 4-5 share Mana 2, and channels 6-7 share Mana 3. The four 4-20 mA channels in the field incident fell into the same two channel groups, which is consistent with all four going to 7FFF when a single transducer was connected.

SM 331 input stage - Mana reference topology Channel group 0/1 M+ M- Mana (open!) Differential Amplifier MUX / ADC 13 bit CPU reads 7FFF on every channel that shares Mana If Mana is missing, open, or cross-wired to L+ (24 V), the differential input loses its return path. Every channel using that Mana rail reads the saturated positive rail, encoded as 7FFF.

Root Cause Analysis

Field experience with the 6ES7331-7KF02-0AB0 and similar SM 331 variants reduces the multi-channel 7FFF symptom to five typical root causes. Each one should be ruled in or out before the module is replaced.

Cause 1: Broken Mana wire

Most common. A 4-wire (separately powered) transducer provides M+ and M- for the loop current and a separate U+, U- for the 24 V supply. The "-" of the loop (Mana) must return to the SM 331 Mana terminal. If that wire is open at the plug, lifted at the terminal block, or cut in the conduit, the input stage of the module floats. The result is every channel on the same Mana group reading 7FFF (or random full-scale noise). A repaired Mana wire on the same incident cleared the symptom immediately.

Cause 2: Cross-wired Mana to L+ (24 V supply)

When a 2-wire loop-powered transducer is wired, Mana on the SM 331 should connect to M (24 V common) at the transducer end. If the technician mistakenly ties Mana to L+ (24 V supply) or to the shield, the input stage is biased to a rail. Channels on that Mana group saturate positive to 7FFF. Always separate the analog Mana return from the power M rail when the device is 4-wire, and tie them only at a single, intentional point when the device is 2-wire.

Cause 3: Short between M+ and Mana at the transducer

A failed transducer can short M+ to its own Mana (or to its case). The 24 V loop supply then drives the SM 331 input beyond common-mode range; the protection clamp conducts and again the differential pair saturates. Replacing the transducer is the only fix.

Cause 4: Defective module input stage

Less common but real. If the input op-amp of a channel group is damaged (for example by an over-voltage event or hot insertion), every channel on that group reads 7FFF. In the field incident, the module had been swapped for a brand new unit, ruling this out: the original card was already known good in another slot.

Cause 5: HW Config mismatch with the wiring

If HW Config is set to "Voltage" but the field is wired as current, the input stage behaves as a high-impedance voltmeter and the reading is undefined (typically 7FFF or noisy). The "Measuring" drop-down in HW Config must match the field wiring. Per the S7-300 Module Data manual, current mode 4-20 mA requires the "Measuring" range to be set to "Current (4-wire transducer)" or "Current (2-wire transducer)" depending on how the device is powered.

The Mana Terminal and 4-20 mA Wiring

Each channel group has a dedicated Mana terminal on the 20-pin front connector. For a 4-wire transducer, the wiring is:

SM 331 4-wire current transducer wiring SM 331 6ES7331-7KF02 M+ (ch 0) Mana (ch 0) M+ (ch 1) Mana (ch 1) 4-wire transducer 4-20 mA loop (e.g. Festo 0-10 bar) Channel 0 current (M+) Channel 0 Mana return - MUST be wired Channel 1 current (M+) Channel 1 Mana return - MUST be wired Open Mana - input stage floats - 7FFF on every channel of that group.

For 2-wire loop-powered transmitters, the transducer draws its supply current from the loop. The SM 331 front connector ties the 24 V supply of the loop internally to M+, so a 2-wire device only needs M+ and Mana wired back to the module. The HW Config "Measuring" range must be set to "Current (2-wire transducer)".

Shielding note: The analog cable shield must be bonded at one end only, typically at the cabinet, to avoid ground loops that inject 50/60 Hz common-mode and push Mana away from its 0 V reference. Bundling analog and 24 V power in the same conduit is also a frequent source of cross-coupled noise that can drag the input stage around full-scale.

Hardware Configuration Diagnostic Settings

Two module properties in STEP 7 HW Config are relevant to the 7FFF symptom:

  1. "Measuring" per channel group must match the physical wiring. For 4-20 mA 4-wire select "Current (4-wire transducer)" or for 2-wire select "Current (2-wire transducer)".
  2. "Diagnostic interrupt" check box enables the diagnostic interrupt. With it enabled, an overflow or wire break fires OB82 and writes an entry to the diagnostic buffer.

To enable diagnostics in STEP 7 V5.x:

  1. Open HW Config and double-click the SM 331 module.
  2. Select the "Addresses" or "Inputs" tab.
  3. Tick "Diagnostic interrupt" under "Module properties".
  4. Set the diagnostic type to "Wire break" (only available for current and RTD ranges).
  5. Compile and download the HW Config to the CPU.

In the TIA Portal, right-click the SM 331 in the device view, choose "Properties -> Diagnostics", and enable the same interrupts. The portal generates an OB82 block on download if one does not already exist.

Without these checkboxes enabled, the module still returns 7FFF on overflow or wire break, but OB82 is not called and the diagnostic buffer stays empty, which is exactly what the field incident reported. The module is fully functional, it is just not being asked to report.

Diagnostic Buffer and OB82 Handling

Once the diagnostic interrupt is enabled, any of the following events writes a diagnostic entry and triggers OB82:

SM 331 diagnostic events (channel-group granularity)
Event OB82 flag (local data) Channel group affected Typical cause
Wire break Bit pattern in module-specific data, channel group byte Group of 2 channels Open Mana, open M+, or 4-20 mA signal below 3.6 mA
Overflow Overflow bit in group status Group of 2 channels Input signal above range, e.g. 21 mA on a 4-20 mA channel
Underflow Underflow bit in group status Group of 2 channels Input signal below range, e.g. 3.9 mA on a 4-20 mA channel
Module parameter assignment error OB82_MDL_DEFECT bit 15 Whole module HW Config mismatch (voltage/current) or wrong measuring range
Front connector missing OB82_MDL_DEFECT bit 13 Whole module Connector not seated
External fault (sensor supply) OB82_MDL_DEFECT bit 11 Whole module 24 V sensor supply missing or shorted

Read the diagnostic buffer in STEP 7 via "PLC -> Module Information -> Diagnostic Buffer". The text entry will name the channel group ("Channel 0/1" or "Channel 2/3", etc.) and the fault type. In the TIA Portal, use "Online & Diagnostics -> Diagnostics". The S7-300 / S7-400 system and standard functions reference lists every event ID and its meaning, including the exact channel-group encoding.

Inside OB82, the local data word OB82_MDL_DEFECT tells you whether the fault is incoming or outgoing. The SM 331 module manual provides the full per-channel diagnostic byte layout for STEP 7 V5.x; in TIA Portal the symbolic names (for example iQC_ChannelGroup0, iQC_ChannelGroup1) are exposed automatically.

Step-by-Step Field Diagnostic Procedure

The following sequence isolates a multi-channel 7FFF condition in the shortest possible time and is the procedure that should have caught the field incident earlier.

Prerequisites

  • STEP 7 V5.5+ or TIA Portal V13+ programming device online to the CPU
  • Calibrated multimeter with mA DC range and a 24 V DC supply
  • Spare 250 ohm precision resistor for current loop simulation (4-20 mA to 1-5 V test)
  • Spare 20-pin front connector (6ES7392-1AJ00-0AA0 screw or 6ES7392-1BJ00-0AA0 spring)
  • Copy of the HW Config and the wiring diagram

Procedure

  1. Online -> diagnostic buffer. If the buffer is empty, the diagnostic interrupt is not enabled. Enable it per the previous section and download HW Config. If the buffer already shows a wire break on "Channel 0/1" or whichever group, the suspect channel is identified; go to step 4.
  2. Monitor the raw input value in a VAT (Variable Table) for every configured channel. Note which channels read 7FFF and which read a sensible value (e.g. 0C00hex for 12 mA). All 7FFF channels will normally be on the same Mana group.
  3. Check HW Config. Right-click the SM 331, "Properties -> Inputs". For each channel group confirm "Measuring = Current (4-wire)" or "Current (2-wire)" as appropriate, and "Diagnostics = enabled".
  4. De-energise the field, isolate the suspect channel. Open the front connector. Using a current source, inject 12 mA into the suspect M+ / Mana pair. If the suspect channel now reads a sensible value, the field wiring or the transducer is at fault. If it still reads 7FFF, the module input stage is at fault (swap module).
  5. Loop-current measurement at the module end. With the transducer still connected and energised, break the Mana return at the SM 331 terminal and put the multimeter in series. Expected: 4-20 mA. If the multimeter reads 0 mA, the loop is open (broken wire, dead transducer, or wrong polarity).
  6. Mana-to-M voltage check. With the loop live, measure DC volts between Mana and the cabinet M (24 V common). Expected: less than 1 V. If you read the full 24 V, Mana has been cross-wired to L+ at the transducer end.
  7. Cold check of the transducer. Power down the loop. Measure resistance of the transducer between M+ and Mana. Expected: a few hundred ohms (loop input resistance), not open and not zero. Zero ohms means a short inside the transducer; infinite ohms means an open coil.
  8. Plug and socket inspection. Pull the 20-pin front connector and visually inspect the screw terminals. Loose strands of stranded wire bridging Mana to M+ at the connector is a recurring field failure.
  9. Spare-slot reproduction test. Move the suspect transducer to a spare channel on a different Mana group. If the original group now reads correctly and the new group reads 7FFF, the transducer is damaged. If both groups read 7FFF, the Mana wiring is the same (probably a multi-pair cable).
  10. Restore, monitor, document. Re-energise, observe the diagnostic buffer is clear, and update the wiring diagram with the corrected conductor colour and terminal number.

Verifying Channel Group Behaviour

After the wiring repair, validate the fix without disturbing production. Four verification methods work in parallel:

Verification methods after Mana or transducer repair
Method What it confirms How to run
Online raw value check All 4-20 mA channels on the affected Mana group now read within 0 to 27648 Open a VAT in STEP 7 or TIA, monitor IW.. for every channel. Apply a known pressure and confirm the value tracks.
Diagnostic buffer No new wire break or overflow events Clear the buffer (PLC -> Module Information -> Clear buffer), then leave the system running 30 minutes. Re-read the buffer; it must be empty.
Loop current at the transducer 4 mA at 0 bar, 20 mA at 10 bar (Festo 0-10 bar gauge) Clamp-on or break-loop multimeter. Compare to the pressure value displayed by the transducer.
Common-mode voltage Mana rail at 0 V +/- 1 V referenced to cabinet M DC voltmeter from Mana terminal to PE. Anything above +/- 2 V is a ground loop.

Pressure Transducer Considerations (Festo 0-10 bar)

The field incident used a Festo pressure gauge with 4-20 mA output corresponding to 0-10 bar. Festo transducers of this class (SDE1, SDE5, SPAE, SPAU variants) are 2-wire loop-powered by default and use an M12 connector with a prewired 4-pin plug. The pin assignment for the SPAE and SDE1 families is typically:

Festo SDE / SPAE 4-20 mA connector pinout (typical)
Pin Function Wire colour (typical)
1 Loop + (24 V) Brown
2 Loop - (Mana) White
3 Digital output (switching) Blue
4 Digital ground or not used Black

Always verify against the specific Festo datasheet for the part number in service: pinout varies between product families and between the 2-wire and 4-wire variants of the same family.

Because the device is 2-wire, the SM 331 must be configured as "Current (2-wire transducer)". If HW Config is set to 4-wire, the module expects a separate 24 V supply and the input stage will saturate. Conversely, if a 4-wire transducer is connected with the 2-wire setting, the input stage is missing its return and reads 7FFF on the group.

Hot-swap warning: Never connect or disconnect a 4-20 mA loop while the module is in RUN, particularly with a 2-wire device, without first opening the loop. The inrush current can latch the input stage and pull the whole group to 7FFF until power-cycle. This is the most common cause of "module has been replaced, fault still present" in the field.

Field Commissioning Checklist

Use this checklist on any new SM 331 installation, or after a wire repair, to prevent the multi-channel 7FFF symptom recurring.

  • HW Config "Measuring" range matches the wiring (4-wire vs 2-wire current, voltage, RTD)
  • "Diagnostic interrupt" enabled per channel group
  • OB82 (or its TIA equivalent) downloaded and instrumented with a buffer write
  • Mana terminal screw torqued to 0.6 Nm and tug-tested
  • Shield bonded at cabinet end only, isolated at transducer end
  • Loop current measured at module end (4 mA at zero, 20 mA at full scale)
  • Common-mode voltage Mana-to-M measured below +/- 2 V
  • Diagnostic buffer empty for 30 minutes under load
  • Wire colour and terminal number recorded on the as-built drawing

Why the Original Diagnostic Buffer Was Empty

The field incident reports that HW Config showed no diagnostic message even with the faulty transducer connected. There are three common reasons, in order of frequency:

  1. Diagnostic interrupt not enabled in the module properties. The most likely cause in this case, given the symptom was present on a brand new card. Without the check box, OB82 is never called.
  2. OB82 is not loaded on the CPU. The CPU ignores the interrupt if the OB is missing: the diagnostic event is queued but not reported in the buffer. Place a "beeper" inside OB82 (set a marker, write to a flag byte) to confirm the OB is firing.
  3. Wire break detection is not active for the configured range. Some ranges (for example voltage below 1 V) do not have wire break detection enabled. For 4-20 mA the detection is automatic once the range is set correctly in HW Config.

Re-enable the diagnostic interrupt, download, and re-test before drawing any conclusion about the module being defective.

Troubleshooting Matrix

Symptom to root cause matrix for SM 331 6ES7331-7KF02-0AB0
Symptom Most likely cause Quick test Fix
All channels of one group read 7FFF Open Mana return Measure Mana-to-M voltage at module Repair or replace Mana wire
Single channel reads 7FFF, group OK Broken wire to that transducer Measure loop current at terminal Replace cable or transducer
All channels of one group read 7FFF, Mana at 24 V Mana cross-wired to L+ Trace cable, check terminal assignments Re-wire to correct Mana terminal
One channel reads 7FFF, others noisy Shielding or ground loop Disconnect shield at field end, observe Bond shield at cabinet only
All channels read 7FFF after hot-swap of transducer Input stage latched Power-cycle the module Add SOP: open loop before swap
Value correct in HW Config, wrong at runtime HW Config not downloaded after edit Check "Hardware configuration matches" warning Download HW Config to CPU
New module, same fault on new module Wiring fault, not module Move transducer to a known good channel on a different group Repair field wiring

Frequently Asked Questions

What does 7FFF mean on a Siemens SM 331 analog input?

7FFFhex (decimal 32767) is the encoding for "overflow or wire break" in the SM 331 input word. On a 4-20 mA channel it appears whenever the loop current is below 3.6 mA, above 22.8 mA, or the Mana return is open. It is not a real measured value and must be filtered in the application code.

Can one bad channel force all other channels of an SM 331 to 7FFF?

Yes, if the fault affects the Mana reference that those channels share. The 6ES7331-7KF02-0AB0 groups channels in pairs (0/1, 2/3, 4/5, 6/7). A broken Mana wire or a shorted transducer on one channel can pull every channel of that group, and groups that share the same multi-pair cable, to 7FFF.

How do I enable wire break detection on 6ES7331-7KF02-0AB0?

In HW Config, double-click the module, go to "Inputs", and for each channel group set "Measuring" to "Current (4-wire)" or "Current (2-wire)" as appropriate, then tick "Diagnostic interrupt" and "Wire break". Download the HW Config. The diagnostic event then fires OB82 and writes to the diagnostic buffer.

Is it safe to hot-swap a 4-20 mA transducer on a live S7-300 system?

No. Always open the loop at the terminal block before connecting or disconnecting a transducer. Inrush current on connection, or back-EMF on disconnection, can latch the input stage and drive the channel group to 7FFF until the module is power-cycled. This is the most common cause of "phantom" faults after maintenance.

How do I check the diagnostic buffer for a specific channel group?

In STEP 7 V5.5, choose "PLC -> Module Information -> Diagnostic Buffer". Look for an entry containing "Channel x/y" and "wire break" or "overflow". In the TIA Portal, select the SM 331 online and open "Diagnostics". The buffer lists the channel group explicitly, so you can map the event back to a physical transducer.

The module has been replaced but the fault is still present. Why?

Two reasons dominate: (1) the fault is on the Mana wiring or the transducer, not the module, and the new card sees the same floating reference; (2) the diagnostic interrupt is not enabled, so the new card's diagnostics never get read. Enable diagnostics, download HW Config, and re-test before ordering a third card.

What is the correct HW Config setting for a Festo 2-wire 4-20 mA pressure gauge?

Set "Measuring" to "Current (2-wire transducer)" for the channel group the gauge is wired to, enable "Diagnostic interrupt" and "Wire break", and confirm the wiring returns Mana to the dedicated Mana terminal of that group, not to M (24 V common) or to PE. Verify the Festo pinout for the specific part number before terminating the M12 plug.

Back to blog