SINAMICS S120: Read Only Active Alarms via r2122 and r2125

David Krause18 min read
SiemensTechnical ReferenceVFD / Drives
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem: r2122 Returns History, Not Active State

When a PLC uses ReadDriveParameter to poll alarm state from a SINAMICS S120, the function returns the eight-slot alarm buffer r2122[0..7]. The buffer is populated on every new alarm and is not cleared when the operator acknowledges the alarm from STARTER, Scout, an AOP30 panel, or an HMI. The buffer continues to display alarm codes that were already acknowledged (and possibly occurred days ago) until newer alarms push them out of the eight-position ring.

This produces a recurring field-failure mode: STARTER/Scout shows no active alarms, but ReadDriveParameter on r2122 still returns a non-zero value at index 0. The PLC concludes the drive is in alarm state, the operator disagrees, and the HMI is stuck in a latched alarm banner that will not release.

The root cause is a mismatch between two distinct data sets the drive exposes:

  • Alarm buffer (r2122) – a sliding history of the last eight alarms, including acknowledged entries.
  • Active alarm state – the subset of buffer entries whose acknowledgment time is still zero.

Reading the buffer alone is not enough. The reliable per-entry filter is the acknowledgment-time parameter r2125, which is zero for any alarm that is still active and non-zero once the alarm has been cleared by an explicit Acknowledge command.

Field-discovered limitation of p2111: the counter p2111 returns the number of alarm slots occupied in the buffer, not the number of alarms that are still active. Acknowledged entries remain in the buffer until they are overwritten by a newer alarm, so p2111 stays non-zero long after the last alarm has been cleared. Do not wire p2111 as a binary "any active alarm" flag.

SINAMICS S120 Alarm and Fault Model

The SINAMICS S120 distinguishes three categories of drive event. The official definitions are in the SINAMICS S120/S150 List Manual (function diagrams 8030 and 8060):

Category Identifier Severity Default Drive Reaction Ack via
Fault Fxxxxx OFF1 / OFF2 / OFF3 trip Pulse inhibit, status bit set p3981 / AOP30 / STARTER
Alarm Axxxxx Warning only Display only, drive continues p3981 / AOP30 / STARTER (HMI-level)
Safety message Cxxxxx SIL-relevant Functional safety channel Safety Integrated logic

Alarms do not stop the drive. They appear in STARTER/Scout, on the AOP30 operator panel, and in the buffer r2122. Once the underlying condition is gone, the alarm can be acknowledged (extinguished) by a positive edge on p3981, by the AOP30 ACK key, or by the Acknowledge all faults button in the commissioning tool. Acknowledgment does not erase the buffer entry – it stamps the entry with the acknowledgment time.

For PLC-side reading, this distinction is critical: ReadDriveParameter on r2122 returns the buffer, not the active state. The buffer is a sliding window of up to eight of the most recent alarms. The window slides only when a new alarm arrives. Acknowledgment does not move the window.

Buffer Architecture: r2122, r2123, r2124, r2125

For each alarm slot, the S120 stores a tuple of four indexed parameters. The index space is shared across all four, so slot i in one parameter refers to the same logical event as slot i in the others:

Parameter Datatype Content
r2122[0..7] U16 Alarm number Axxxxx
r2123[0..7] U32 (ms since CU power-on) Time the alarm was raised
r2124[0..7] Float Alarm value (analog qualifier, e.g., threshold reading)
r2125[0..7] U32 (ms since CU power-on) Time the alarm was acknowledged; 0 = still active

All four arrays share the same slot semantics described in the next section. The PLC should always read r2122[i] and r2125[i] in lockstep to avoid index drift caused by a new alarm arriving between reads.

r2122 Buffer Structure: Eight Slots, Oldest to Newest

r2122 is an array parameter with indices 0 through 7. Each element is a U16 (unsigned word) holding the alarm number Axxxxx. The List Manual function diagram 8030, paragraph 7.3.2, defines the indexing convention:

  • r2122[0] – the oldest alarm currently held in the buffer.
  • r2122[7] – the most recent alarm.

The buffer behaves as a FIFO ring. When a ninth alarm arrives, r2122[0] is overwritten and the new alarm is placed at r2122[7]. Slots that are not yet filled contain 0.

r2122[0..7] Alarm Buffer (oldest left, newest right) A50800i=0 A07500i=1 A03100i=2 A01205i=3 A05200i=4 A07400i=5 A01250i=6 A05050i=7 oldest → ← newest r2125[i] > 0 → alarm at index i has been acknowledged (HISTORY) r2125[i] = 0 → alarm at index i is still ACTIVE r2122[i] = 0 → empty slot (alarm has been pushed out of the 8-deep ring) Per FD 8030, [0] is oldest and [7] is most recent. Acknowledge does not move the window.

The buffer is reset only on a Control Unit power cycle, a project download, or a factory reset (p0976 = 1). Local acknowledgment clears the display in STARTER/Scout but leaves the buffer populated until a new alarm rotates the entry out.

p2111: The Coarse Total-Count Counter

p2111 is the alarm counter. It returns the number of alarms currently held in the buffer, capped at 8. It is a useful first read because it bounds the work the PLC must do: there is no point in reading more than p2111 entries.

The S120 List Manual states that p2111 is incremented every time a new alarm is registered and decremented when the corresponding buffer entry is removed. In practice this means p2111 is monotonic in the short term (between alarm events) and falls only when a slot is overwritten by a newer alarm. If a slot is acknowledged, the slot stays full and p2111 stays high.

Use p2111 as a bound, not as a status:

// Read p2111 to know how many slots of r2122 to bother reading
n := ReadDriveParameter(driveID := #drvId, paramNo := 2111, subIndex := 0);
IF n > 8 THEN n := 8; END_IF;
// n is the upper bound for the iteration in the next section

r2125: Acknowledgment Time – The Reliable Active-Only Filter

r2125 is the array of acknowledgment timestamps, indexed identically to r2122. The value is the time in milliseconds since the Control Unit powered on at which the alarm was acknowledged by an Acknowledge command (p3981, AOP30 ACK key, STARTER Acknowledge all faults).

r2125[i] value Meaning PLC interpretation
0 Alarm at r2122[i] is still active or has not been acknowledged SHOW AS ACTIVE
> 0 Alarm was acknowledged at the timestamp shown HISTORY – do not display

For the PLC, the algorithm is therefore: read r2122[i] and r2125[i] for i = 0..7; keep the (r2122[i], r2125[i]) pair only if r2125[i] = 0 AND r2122[i] <> 0. The result is the live, active-only alarm list that matches the STARTER/Scout online view.

If the drive has been power-cycled, r2125 returns to 0 for all slots, so any alarm that comes back after power-up looks "active" until acknowledged – which is the correct behavior. The power-on time base for r2125 is the same as the r2123 raise time, so an alert with r2125[i] < r2123[i] indicates a buffer slot that was kept across an acknowledgment event but is still pre-raise (rare edge case during CU initialization).

Step-by-Step Procedure to Read Only Active Alarms

The procedure below works for any controller that exposes the standard Siemens ReadDriveParameter access (S7-1500 / S7-1200 with SINA_INFU / SINA_SPEED, S7-300/400 via DriveES, TIA Portal with Startdrive, or a third-party controller using PROFIdrive acyclic parameter channel).

  1. Establish acyclic communication. Confirm the PROFIdrive acyclic channel is up by reading p2051[0] (telegram check) or a known parameter such as r0021 (actual speed smoothed). If acyclic reads time out, all buffer values are stale and untrustworthy.
  2. Read p2111. This is the alarm count currently held in the buffer (0..8). Use it as an upper bound on the number of slots you need to evaluate. If p2111 = 0 the drive has no alarms at all and the read is complete.
  3. Read r2122[0..7]. Issue eight single-element reads (or one multi-element read where the controller supports it) to obtain the eight alarm codes. Slots that are unused return 0.
  4. Read r2125[0..7]. For each non-zero r2122[i], read r2125[i] to determine whether the alarm has been acknowledged.
  5. Filter active entries. Keep (r2122[i], r2125[i]) only if r2122[i] <> 0 AND r2125[i] = 0.
  6. Display or act on the filtered list. The resulting array contains only currently active alarms – the same set STARTER/Scout shows in its alarm window.
Atomic-read caveat: Always read r2122 and r2125 in the same PROFIdrive acyclic transaction frame. A new alarm arriving between the two reads leaves the index out of sync – r2122[5] may correspond to a different event than r2125[5]. The PROFIdrive DO100 acyclic access guarantees atomic reads of a single indexed parameter, but a multi-parameter read is not atomic across the drive. If your library supports request batching, batch the r2122 and r2125 reads with minimal delay between them.

PROFIdrive Acyclic Parameter Channel Mechanics

Read/write access to r2122, r2125, and p2111 goes over the PROFIdrive acyclic parameter channel, defined in the PROFIdrive profile V4.2 (and V5.0 in current PN stacks). The channel uses the same PROFINET connection as cyclic process data, but operates on demand by the controller.

Two request primitives are used:

  • Request parameter – read one or more parameters. Used for r2122, r2125, p2111.
  • Change parameter – write one or more parameters. Used to issue p3981 = 1 for Acknowledge.

Each request specifies a parameter number, a subindex (the array index for r2122[i]), and an attribute (value, name, text, default). The drive returns the value, the data type, and an error code if the access failed. Typical error codes on this path:

Error code (hex) Meaning Likely cause
0x0000 Success —
0x0001 Invalid parameter number Wrong drive object or wrong slot
0x0002 Invalid subindex Index out of range (e.g., asking for r2122[8])
0x000B No operation priority Drive is in commissioning, not operation
0x000F Text array not present Asking for text, only value exists
0x0010 / 0x0011 No write / write protected Tried to write a read-only parameter

On an S7-1500 with the Startdrive / DriveLib ReadDriveParameter function block, the BUSY, DONE, and ERROR outputs map directly to the PROFIdrive request state machine. Always check ERROR on each call and treat a TRUE ERROR as a stale value – do not latch it into the HMI.

Code Example: S7-1500 SCL Block for Active-Only Alarm Read

The SCL (Structured Control Language) snippet below reads p2111, r2122, and r2125 from a SINAMICS S120 via the standard SINA_INFU / SINA_SPEED data blocks. Adapt the instance names to your project. This block is intended for use with the Startdrive / DriveLib library; the call shape matches the standard ReadDriveParameter API.

// FB_ActiveS120Alarms - returns only currently active alarms
// Inputs : i_driveAxis   - axis reference (AXIS_REF from SINA_INFU)
// Outputs: o_activeCodes - ARRAY[0..7] OF UINT  (active alarm numbers)
//          o_activeCount - INT                   (number of active alarms)
//          o_error       - BOOL                  (comm error, no valid result)

VAR
    nBufferCount  : UINT;        // p2111
    aCode         : ARRAY[0..7] OF UDINT;   // r2122[i]
    aAckTime      : ARRAY[0..7] OF UDINT;   // r2125[i]
    i             : INT;
    bOk           : BOOL;
END_VAR

// reset outputs
o_activeCount := 0;
o_error       := FALSE;
FOR i := 0 TO 7 DO
    o_activeCodes[i] := 0;
END_FOR;

// --- Step 1 : read p2111 alarm count ---
bOk := ReadDriveParameter(
    axis       := i_driveAxis,
    parameter  := 2111,
    subindex   := 0,
    value      := nBufferCount );

IF NOT bOk THEN
    o_error := TRUE;
    RETURN;
END_IF;

IF nBufferCount > 8 THEN
    nBufferCount := 8;
END_IF;

// --- Step 2 : read r2122 (codes) and r2125 (ack times) in lockstep ---
FOR i := 0 TO 7 DO
    aCode[i]    := 0;
    aAckTime[i] := 0;
END_FOR;

FOR i := 0 TO 7 DO
    bOk := ReadDriveParameter(
        axis      := i_driveAxis,
        parameter := 2122,
        subindex  := i,
        value     := aCode[i] );
    IF NOT bOk THEN o_error := TRUE; CONTINUE; END_IF;

    bOk := ReadDriveParameter(
        axis      := i_driveAxis,
        parameter := 2125,
        subindex  := i,
        value     := aAckTime[i] );
    IF NOT bOk THEN o_error := TRUE; CONTINUE; END_IF;
END_FOR;

// --- Step 3 : keep only the slots where the alarm is still active ---
FOR i := 0 TO 7 DO
    IF (aCode[i] <> 0) AND (aAckTime[i] = 0) THEN
        o_activeCodes[o_activeCount] := UINT#TO_WORD(aCode[i]);
        o_activeCount := o_activeCount + 1;
    END_IF;
END_FOR;

Ladder Logic Reference

For teams running on S7-300 / S7-400 with DriveES, the same logic in ladder uses two parallel ReadDriveParameter coils driving the same axis reference, with the second rung gated on the first rung's OK bit. The index 0..7 is generated by an up-counter that resets at 8:

Network 1: trigger acyclic read of r2122[i]
      [EN] ----[ CALL ReadDriveParameter
                  axis      := DB_Axis
                  parameter := 2122
                  subindex  := Z0 (counter 0..7)
                  value     := DB_Alarm.Code[Z0] ]
              ----( OK )----[ ZV Z0, preset 8 ]

Network 2: read r2125[i] only when r2122[i] is valid
      [EN] ----[ Code[Z0] <> 0 ]----[ CALL ReadDriveParameter
                                        axis      := DB_Axis
                                        parameter := 2125
                                        subindex  := Z0
                                        value     := DB_Alarm.AckTime[Z0] ]
                                    ----( OK )----[ ]

Network 3: filter active entries
      [EN] ----[ Code[Z0] <> 0 AND AckTime[Z0] = 0 ]----[ INC DB_Alarm.ActiveCount
                                                         MOV Code[Z0] -> DB_Alarm.ActiveCodes[DB_Alarm.ActiveCount] ]

For S7-1200 / S7-1500 in TIA Portal with Startdrive, the SCL block above is preferred because TIA Portal's LAD/FBD editor does not expose indexed acyclic parameter reads as cleanly as classic STEP 7.

Cross-Verification with STARTER / Scout

To prove the algorithm is working, perform the following cross-check during commissioning:

  1. Open STARTER (or TIA Portal with Startdrive) and connect to the drive online.
  2. Navigate to Diagnostics > Alarms. Note the active alarm codes shown in the online alarm window.
  3. Run the PLC block above and capture o_activeCodes.
  4. The two lists must match exactly – same codes, same order, same count.
  5. Click Acknowledge all faults in STARTER.
  6. Re-read. Both lists must be empty.
  7. Force a known alarm (e.g., disconnect an encoder cable to trigger A07500, or write p1230 = 0 on a drive configured for p1230 = 1). Repeat the read and confirm the new code appears at [7].

If STARTER shows no active alarms but the PLC block still returns a code, the most common cause is that the PLC is reading an alarm that was acknowledged after it was placed in the buffer. Confirm r2125[the_index] – it must be non-zero for any entry that STARTER is not showing.

Extended Diagnostics: r2132 Status Word

For controllers that prefer a bit-mapped status rather than an alarm-code list, the S120 also exposes r2132, a 16-bit status word. The List Manual defines the bit mapping: bit 0 = alarm 1, bit 1 = alarm 2, etc., up to bit 15 = alarm 16. The mapping is not contiguous for higher alarm numbers; they are assigned according to a fixed lookup table published in the manual.

r2132 is convenient for a quick "is the drive in any alarm state" poll: read the word, OR all bits, and the result is non-zero if any alarm is active. However, the bit mapping is sparse and varies between firmware branches, so this approach is brittle. The (r2122, r2125) pair is the recommended method for code-level identification.

Alarms vs Faults: Reading Active Faults (r2134, r2137)

Faults (Fxxxxx) follow an analogous but separate parameter set. The structure is parallel to alarms:

Concept Alarms (A) Faults (F)
Buffer r2122[0..7] r2134[0..7]
Time received r2123[0..7] r2135[0..7]
Value r2124[0..7] r2136[0..7]
Ack time r2125[0..7] r2137[0..7]
Counter / active count p2111 (max 8) r2130 / p2131 (varies by firmware)
Acknowledge primitive p3981 positive edge p3981 positive edge

ReadDriveFaults (as opposed to ReadDriveParameters) on a SIMATIC controller typically reads r2134 directly and applies the active-filter logic in firmware, which is why faults come back cleanly from the function. The alarms path has historically been a ReadDriveParameter (raw parameter) path, which is why the historical-buffer issue surfaces on the alarm path and not on the fault path.

Library Differences and Firmware Notes

Library / Tool Read API for alarms Behavior
S7-1500 Startdrive DriveLib ReadDriveParameter on 2122 / 2125 Raw parameter access, must apply filter
S7-300/400 DriveES SIMATIC ReadDriveParameter on 2122 / 2125 Same as above
S7-1200 DriveLib ReadDriveParameter on 2122 / 2125 Same as above
Simotion SCOUT (legacy) Direct system variable alarmBuffer Filtered by SCOUT runtime
Web server (S120 with FW >= 4.7) JSON over HTTPS Filtered server-side; includes timestamp and ack state

Firmware V4.x to V5.x migration: the parameter numbers (2111, 2122, 2125) are stable across V4.x SPx and V5.x SPx. The semantics of p2111 changed slightly in V4.5 to count all buffer entries including acknowledged (older V4.2 builds returned the count of active-only entries in some DO types). When migrating, re-validate the algorithm against the actual firmware List Manual you target – do not assume a behavior based on a previous project.

Common Pitfalls and Field-Discovered Behavior

Symptom Root cause Fix
PLC reads r2122[0] non-zero but STARTER shows no active alarm Alarm was acknowledged; r2125[0] is non-zero Apply r2125[i] = 0 filter as shown above
PLC always returns 0 even though alarm is active Wrong index orientation – reading r2122[0] when newest is at [7] Iterate the full [0..7] range, do not assume [0] is newest
PLC returns different list from STARTER New alarm arrived between r2122 read and r2125 read Re-read both, or read in same acyclic transaction
r2125 = 0 for an alarm the operator has already cleared Power cycle reset the ack time stamp Correct behavior after a power cycle; do not re-acknowledge in PLC
p2111 returns 0 but r2122 has a value at index 0 Library is reading p2118 or p2119 by mistake (related but different parameters) Verify parameter number 2111 exactly in the ReadDriveParameter call
ReadDriveParameter times out on S120 Acyclic channel not open; PROFINET name/IP mismatch Confirm p2051 / p0922 telegram, then re-try
Alarm disappears from PLC list but STARTER still shows it PLC read p3981 = 1 accidentally; drive acknowledged all alarms Guard the p3981 write with operator confirmation
Alarm re-appears after PLC restart (warm restart of CPU) PLC kept a latch, drive has historical entry Re-apply the r2125 filter on every read cycle, not just on first scan
List is empty even when drive has Safety Integrated alarm Cxxxxx r2122 is the alarm buffer, not the safety message buffer Read the safety-specific buffer; refer to S120 Safety Integrated manual

Troubleshooting Matrix

Check Tool / Parameter Pass condition Fail action
PROFIdrive acyclic channel up Read p2051[0] or r0021 Returns a value < 5 s Fix PROFINET name, IP, or telegram
Buffer has alarms Read p2111 0..8 Re-initialize acyclic channel; check drive is in RUN
Filter applied Compare r2122[i] vs r2125[i] For each r2122[i] <> 0, r2125[i] is consistent with operator's view Re-apply filter; cross-check with STARTER
Index orientation Read full r2122[0..7] in one transaction Newest alarm at [7] Reverse loop if library inverts index
Alarm cleared but still shown r2125[i] > 0 Slot is filtered out Ensure filter step is present in code
No alarms in PLC but drive tripped Check r2134 (fault buffer) Fault list may be non-empty Add fault buffer read for trips

Multi-Drive and Network Considerations

On multi-axis S120 systems (one CU320-2 controlling several Motor Modules and Line Modules), each drive object (DO) has its own r2122, r2125, and p2111. The PLC must address the correct DO number in the PROFIdrive parameter access – DO 1 is typically the Control Unit, DO 2..n are the drive objects (one per Motor Module or Line Module). The Telegram Configuration dialog in Startdrive (or the device configuration in STEP 7 HW Config for older projects) defines the DO-to-slot mapping.

For drives behind a PROFINET switch or routed through a PN/PN coupler, the acyclic channel follows the same routing as the cyclic channel – no special configuration is needed. For PROFIBUS behind a DP/DP coupler, ensure the PROFIdrive version matches on both sides; older PROFIdrive V3 acyclic stacks do not support all of the indexed array access used here.

For very large installations, do not poll all drives on every PLC scan. A 100 ms poll cycle on p2111 per drive is enough to detect new alarms; expand to full r2122 + r2125 read only when p2111 has changed. This reduces acyclic-channel load on the PROFINET controller from 8 drives * 17 reads per scan to 8 reads per scan in steady state.

FAQ

Why does r2122 still show old alarms after I have acknowledged them in STARTER?

Because r2122 is an 8-slot history buffer, not a status register. Acknowledgment stamps r2125[i] with the time of acknowledgment but does not erase the r2122[i] entry. The buffer rotates only when a new alarm arrives and pushes an old slot out.

Can I just use p2111 as a "drive has alarm" flag?

No. p2111 returns the number of alarm slots occupied in the buffer, which can include acknowledged (historical) entries. Use r2125[i] = 0 as the per-entry active filter, or read the r2132 status word for a single-bit active-state poll if you need a flag.

Is r2122[0] the newest or the oldest alarm?

Oldest. The List Manual function diagram 8030 defines r2122[0] as the oldest slot and r2122[7] as the most recent. Always iterate the full [0..7] range when filtering for active entries, and do not assume r2122[0] is the live one.

What is the difference between p2111 and p2131?

p2111 is the alarm (A) buffer count, capped at 8. p2131 is the fault (F) count, which behaves differently because faults trip the drive and are handled by the OFF1/OFF2/OFF3 reaction paths. The corresponding fault buffer is r2134 and the corresponding ack-time is r2137.

How do I clear the alarm buffer completely?

Acknowledge does not clear it. The buffer is reset only on a Control Unit power cycle, a project download, or p0976 = 1 (factory reset). Treat the buffer as read-only history; do not attempt to write r2122 from the PLC. The correct way to clear an active alarm is to issue p3981 = 1 on a positive edge once the underlying condition is gone.

Why does my S120 show different r2122 data than an S210 or G120 on the same code?

The S120/S150 List Manual is the reference for S120 specifically. S210 and G120 share the same parameter numbers (2111, 2122, 2125) on SINAMICS V5.x firmware, but the buffer depth and the active-filter behavior are documented in their own List Manuals. Always cross-reference the device-specific manual before assuming identical semantics.

Back to blog