Sinumerik 840D 828D OPC UA Telemetry: Create MyHMI API Access

David Krause11 min read
OPC / OPC UASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Reading Telemetry from Sinumerik 840D sl and 828D: OPC UA and Create MyHMI /3GL

Siemens Sinumerik 840D sl and 828D CNCs expose operating data, axis states, program information, and event timestamps through multiple read-only interfaces. This guide covers the two primary telemetry paths: the OPC UA server embedded in the NCU and the Create MyHMI /3GL programming package (C++ and .NET APIs). Both paths target the same control data, but they differ in deployment, performance, and integration footprint.

Engineering note. Telemetry retrieval is one-way in this scenario. Both OPC UA (read-only nodes) and Create MyHMI /3GL support read operations suitable for SCADA, OEE, and condition monitoring. Control of the CNC requires additional licensed options and is out of scope here.

1. Sinumerik Architecture Relevant to Data Retrieval

Before selecting an API, map the data sources. A 840D sl / 828D installation typically exposes the following data origins:

Data origin Physical location Typical content Recommended access path
NCK (Numerical Control Kernel) NCU / PPU firmware Axis positions, tool data, program states, operating hours, alarm history OPC UA NCK namespace, /3GL API
PLC (SINUMERIK PLC 317 or 319) PLC slot of NCU Machine I/O, status flags, user DBs OPC UA PLC namespace, /3GL API, direct DB read
HMI (SINUMERIK Operate) PCU / TCU / IPC Active program name, channel mode, override, screen context OPC UA HMI namespace, /3GL API
Drive (SINAMICS S120) Drive units on DRIVE-CLiQ Drive states, temperatures, warnings, service data OPC UA drive nodes (S120), PROFIdrive

All four data origins are reachable through the OPC UA server when the appropriate options are licensed. The Create MyHMI /3GL APIs reach the same nodes through the internal Operate component bus, but with a managed .NET or C++ interface.

2. Prerequisites

  1. Hardware: NCU 710.3 / 720.3 / 730.3 (840D sl) or PPU 290.3 / 291.3 / 292.3 (828D). Older NCU 710/720 (without .3) are not OPC UA-capable and require the Create MyHMI path only.
  2. Firmware: SINUMERIK Operate / NCU software version 4.95 SP2 or higher for OPC UA server. Version 4.08 or higher of Create MyHMI /3GL (ReleaseNotes_CreateMyHMI_3GL_V04.08.02 is the latest publicly mirrored revision).
  3. Licensing: Option 6FC5800-0AP67-0YB0 (P67, "SINUMERIK OPC UA Server") must be activated on the CF card license file. Create MyHMI /3GL additionally requires 6FC5800-0AS12-0YB0 (Create MyHMI).
  4. Network: NCU on a routable subnet; the OPC UA endpoint is bound to the X120 (840D sl company network) or X130 (828D) by default. Firewall rules: outbound TCP/4840 (default) or TCP/4841 (if TLS enabled).
  5. Development tools: Visual Studio 2017 or higher for the .NET path, Visual C++ 2017 or higher for the C++ path, plus a UA-.NET-Standard or UA-.NET-Legacy SDK if you are building a custom client (Siemens does not redistribute a generic UA stack inside the /3GL package).

3. OPC UA Server: Activation and Address Space

3.1 Enabling the OPC UA Server

Activating the server is a two-step operation: license enablement in the CF card license file, then runtime configuration through the HMI.

  1. Insert the P67 license on the CF card. Verify in Commissioning → Licenses on SINUMERIK Operate. The line "SINUMERIK Integrate OPC UA Server" must show status set.
  2. Open the Commissioning menu, navigate to OPC UA configuration, and set the endpoint to opc.tcp://<NCU-IP>:4840 for unencrypted, or opc.tcp://<NCU-IP>:4841 for OPC UA Binary with TLS 1.2 (recommended for production).
  3. Generate or import a server certificate (self-signed is acceptable for one-machine deployments; use a CA-signed certificate for multi-site OEE rollouts).
  4. Create at least one user in User administration → OPC UA with the ReadTelemetry role. Anonymous read access is supported but should be disabled on connected systems.
  5. Restart the OPC UA service: HMI menu Commissioning → OPC UA → Restart service, or NCK command pi/ ncu opcua_restart.
The P67 option only enables the server; runtime configuration is stored in /user/system/etc/opcua/opcua.cfg on the active partition. Back up this file before any firmware upgrade, as it is overwritten on a clean install.

3.2 Address Space Layout

The Sinumerik OPC UA server publishes nodes in a hierarchical namespace. The top-level structure is consistent across 840D sl and 828D:

Namespace URI Typical nodes Data type Update interval
ns=4;s=Sinumerik/Nck/Channel/* Channel state, active program, override, tool offset Int32, String, Float 200 ms (default)
ns=4;s=Sinumerik/Nck/Axis/* Actual position, load, temperature, drive state Float, UInt32, String 100 ms (axes), 500 ms (temperature)
ns=4;s=Sinumerik/Nck/OperatingTimes Power-on time, control running time, axis traversing time Duration (ns 0:0:0 format) Event-based (on change)
ns=4;s=Sinumerik/Plc/Var/* Direct mapping of PLC DBs and Merkers Per PLC variable 100 ms (configurable)
ns=4;s=Sinumerik/Events/Alarms Active alarms, history, acknowledgements EventType (UA custom) Event push (subscribe)
ns=4;s=Sinumerik/Drive/S120/* Drive status word, temperature, current, warning bits UInt16, Float, String 50 ms (status), 1000 ms (temperature)

For statistical/operational data, the most relevant paths are:

  • ns=4;s=Sinumerik/Nck/OperatingTimes/PowerOnTime — total power-on hours.
  • ns=4;s=Sinumerik/Nck/OperatingTimes/ControlRunTime — total time the NC was in Run/Automatic/Manual.
  • ns=4;s=Sinumerik/Nck/OperatingTimes/AxisTraverseTime[1..31] — per-axis motion time.
  • ns=4;s=Sinumerik/Events/Alarms/History — alarm event history with timestamp (server-side) and payload (alarm number, clear text, channel).
  • ns=4;s=Sinumerik/Plc/Var/DB<NNN>.DBW<X> — direct read access to PLC data blocks.

Use a generic OPC UA browser (UaExpert, Siemens OPC Scout) to confirm node availability on your specific firmware version. The node count and naming evolve between major firmware releases; always check the Diagnostics → OPC UA → Node list HMI view before wiring up a client.

3.3 Sample OPC UA Client (C#, UA-.NET-Standard)

The following snippet demonstrates a read with subscription for alarm events. It uses the official OPC Foundation UA-.NET-Standard library (not bundled with Sinumerik):

using Opc.Ua;
using Opc.Ua.Client;

var config = new ApplicationConfiguration {
    ApplicationName = "SinumerikTelemetryClient",
    ApplicationType = ApplicationType.Client,
    SecurityConfiguration = new SecurityConfiguration {
        AutoAcceptUntrustedCertificates = true   // demo only - replace with store in production
    },
    ClientConfiguration = new ClientConfiguration()
};
await config.ValidateAsync(ApplicationType.Client);

var endpoint = CoreClientUtils.SelectEndpoint(
    "opc.tcp://192.168.214.1:4840", useSecurity: false, 1500);
var session = await Session.Create(config, endpoint, false,
    "TelemetryClient", 60000, null, null);

// One-shot read: total operating hours
var opHours = session.ReadValue("ns=4;s=Sinumerik/Nck/OperatingTimes/ControlRunTime");
Console.WriteLine($"Control run time (s): {opHours.Value}");

// Subscription: alarm history
var subscription = new Subscription(session.DefaultSubscription) {
    PublishingInterval = 500
};
var item = new MonitoredItem {
    StartNodeId = new NodeId("ns=4;s=Sinumerik/Events/Alarms/History"),
    AttributeId = Attributes.Value,
    MonitoringMode = MonitoringMode.Reporting
};
item.Notification += (s, e) => {
    foreach (var v in e.NotificationValue.Value as EventFieldList[]) {
        // v.EventFields: [0]=EventId, [1]=SourceName, [2]=Time, [3]=Message, [4]=Severity
        var ts = (DateTime)v.EventFields[2].Value;
        var msg = (LocalizedText)v.EventFields[3].Value;
        Console.WriteLine($"[{ts:o}] ALARM {msg.Text}");
    }
};
subscription.AddItem(item);
session.AddSubscription(subscription);
subscription.Create();
Always run a UA client discovery against the live server before hard-coding NodeIds. Firmware updates may reorganize the address space; using a fixed node list will fail silently on upgrades.

4. Create MyHMI /3GL — C++ API

The Create MyHMI /3GL package (Siemens article ID 109955063) is a C++ component bus that runs inside the SINUMERIK Operate process. It exposes the same data sources as the OPC UA server, but through synchronous .so/.dll calls. Documentation is delivered as the PDF SINUMERIK Operate CPP:

4.1 Component Highlights

  • SlNck — read NCK variables, drive data, operating hours.
  • SlPlc — read/write PLC variables (DB, Merker, Input/Output), with thread-safe access.
  • SlHmi — query active channel, program name, operating mode.
  • SlAlarm — subscribe to alarm queue and history.
  • SlTool — read tool list, magazine assignment, life count.

4.2 Reading Operating Hours (C++)

#include "slnck.h"
#include "slhmi.h"

SlNckConnector* nck = SlNckConnector::instance();
if (!nck->connect("local", 5000)) {
    qCritical("NCK connection failed");
    return -1;
}

// Read control run time in seconds (BTSS variable)
qint64 runSec = 0;
SlNckVariable var("controlRunTime");
if (nck->readVariable(var, &runSec, sizeof(runSec))) {
    qInfo() << "Control run time (h):" << (runSec / 3600.0);
}

// Iterate per-axis traverse time
QStringList axes = nck->getAxisNames();
for (const QString& ax : axes) {
    qint64 t = 0;
    nck->readVariable(SlNckVariable("axisTraverseTime." + ax), &t);
    qInfo() << ax << "=" << (t / 3600.0) << "h";
}

5. Create MyHMI /3GL — .NET API

The .NET variant is targeted at C# or VB.NET applications running on the PCU/TCU/IPC alongside SINUMERIK Operate. See SINUMERIK Operate .NET Programming Manual for the full reference. Components are exposed as .NET assemblies under %ProgramFiles%\Siemens\Automation\SinumerikOperate\bin\3gl\ after installation.

5.1 C# Operating-Hours Read

using Siemens.Sinumerik.Operate._3GL;
using Siemens.Sinumerik.Operate._3GL.Nck;

using var nck = new SlNck();
nck.Connect("local", TimeSpan.FromSeconds(5));

var runTime = nck.ReadVariable<long>("controlRunTime");
Console.WriteLine($"Control run time: {runTime / 3600.0:F1} h");

// Subscribe to alarm history
var sub = nck.CreateAlarmSubscription(TimeSpan.FromMilliseconds(500));
sub.AlarmReceived += (s, e) => {
    Console.WriteLine($"[{e.Timestamp:o}] {e.Number} {e.Text}");
};
sub.Start();

6. Direct PLC DB Access

For custom machine telemetry stored in user PLC data blocks, both OPC UA and Create MyHMI /3GL can read directly. A typical DB mapping for an OEE tag is:

DB offset Type Meaning OPC UA node
DB120.DBX0.0 Bool Cycle active ns=4;s=Sinumerik/Plc/Var/DB120.DBX0.0
DB120.DBD4 Real Cycle time actual (s) ns=4;s=Sinumerik/Plc/Var/DB120.DBD4
DB120.DBD8 Real Cycle time nominal (s) ns=4;s=Sinumerik/Plc/Var/DB120.DBD8
DB120.DBD12 DInt Part counter good ns=4;s=Sinumerik/Plc/Var/DB120.DBD12
DB120.DBD16 DInt Part counter reject ns=4;s=Sinumerik/Plc/Var/DB120.DBD16

Reading DB120.DBD4 with the .NET API:

using Siemens.Sinumerik.Operate._3GL.Plc;
using var plc = new SlPlc();
float cycleTime = plc.ReadFloat("DB120.DBD4");

For the C++ API use slPlc.readFloat("DB120.DBD4") with the equivalent namespace include.

7. OPC UA vs. Create MyHMI: Selection Matrix

Criterion OPC UA Create MyHMI /3GL
Deployment Network client, any host Must run on PCU/TCU/IPC with SINUMERIK Operate
Language Any UA SDK (C#, Java, C++, Python) C++ (component bus) or .NET (managed)
Latency Network round-trip, 50–500 ms typical In-process, sub-50 ms typical
Security TLS 1.2, user/role auth, certificate management Operate user session, no separate security layer
Data model Standard UA, address space browsable Custom API, manual mapping to BTSS variables
Event subscription Standard UA event subscription (MonitoredItem + EventFilter) Callback per component (e.g., SlAlarm.AlarmReceived)
External OEE/SCADA Native, push/pull, OEE tools already UA-capable Requires an extra adapter running on Operate host
Versioning risk Address space changes between firmware releases API changes between /3GL versions; rebuild required
License cost Single P67 option, server only P67 + Create MyHMI option (per-seat)

For greenfield OEE or SCADA projects, OPC UA is the default. For inline HMI extensions and runtime logic embedded in Operate, Create MyHMI /3GL is the lower-latency path.

8. Verification Procedure

  1. Confirm license: HMI → Commissioning → Licenses shows OPC UA Server and (if applicable) Create MyHMI as set.
  2. Open UaExpert (or equivalent) and connect to opc.tcp://<NCU-IP>:4840. Accept the server certificate, then authenticate with the configured user.
  3. Browse the namespace. Verify Sinumerik/Nck/OperatingTimes/ControlRunTime exists and reports a value that increases when the NC is in Run.
  4. Create a MonitoredItem on Sinumerik/Events/Alarms/History with a 500 ms publishing interval. Trigger a known alarm (e.g., remove an enable) and confirm the event is delivered with timestamp, alarm number, and clear text.
  5. Read a PLC variable (e.g., DB120.DBD12) from both the OPC UA client and the /3GL .NET API. Values must match within one update interval.
  6. Force a PLC stop and confirm the OPC UA server continues to deliver cached values and emits the expected ServerStatus_CommunicationFault event.
  7. Capture an HMI screenshot of Diagnostics → OPC UA → Sessions showing the active client session and the configured security policy.

9. Troubleshooting Matrix

Symptom Likely cause Corrective action
UA client cannot reach opc.tcp://<NCU-IP>:4840 P67 not licensed, or wrong network port bound to X120/X130 Verify license under Commissioning → Licenses; check opcua.cfg for the bind address; confirm subnet route
Nodes visible but values static PLC/NCK in stop, or the user lacks read rights Bring PLC to run; check role in User administration → OPC UA
BadNodeIdUnknown on a previously working node Address space changed after firmware upgrade Re-browse, re-map NodeIds, and re-deploy the client
Create MyHMI /3GL call returns SL_ERR_NO_COMPONENT Create MyHMI option missing, or Operate started without /3GL license Verify license and restart SINUMERIK Operate
High latency on alarm events Publishing interval too high, or client polling instead of subscribing Set 200–500 ms publishing interval; use MonitoredItem with EventFilter
TLS handshake fails with certificate error Server certificate not trusted by client trust store Export server cert from HMI and import to client trust store, or use a CA-signed certificate
Operating time counter resets unexpectedly NCK general reset or CF card replacement Re-import license and back up opcua.cfg and license file on every control data save

10. Security and Industrial Integration Notes

Both interfaces are intended to be integrated into a plant-wide industrial security concept. The Sinumerik Operate manual explicitly calls out that the automation and drive components must be embedded in a holistic, state-of-the-art industrial security concept for the plant or machine. Concretely:

  • Restrict OPC UA endpoint to a private subnet; do not expose TCP/4840 or TCP/4841 to the office network.
  • Use OPC UA with TLS 1.2 and a CA-signed certificate when crossing security zones.
  • Disable anonymous authentication once the read clients are configured.
  • Apply the latest SINUMERIK security patches; address space, role definitions, and certificate handling all change between releases.
  • For multi-vendor OEE rollouts, prefer a UA wrapper (e.g., the Siemens Industrial Edge OPC UA Connector or a generic SCADA connector) rather than embedding Create MyHMI on the Operate host.

11. Additional Resources

Which option enables OPC UA on a Sinumerik 840D sl or 828D?

Option 6FC5800-0AP67-0YB0 (P67, "SINUMERIK OPC UA Server") must be set on the CF card license. Activate the endpoint in HMI under Commissioning → OPC UA and restart the OPC UA service.

Can I read alarm timestamps and operating hours without OPC UA?

Yes. The Create MyHMI /3GL package (option 6FC5800-0AS12-0YB0) exposes the same NCK and PLC data through a C++ component bus or .NET assembly. Operating hours are read via the controlRunTime and axisTraverseTime variables, and alarms are delivered through the SlAlarm callback.

What is the default port for the Sinumerik OPC UA server?

TCP/4840 for unencrypted OPC UA Binary and TCP/4841 when TLS 1.2 is enabled. The endpoint is bound to the NCU X120 (840D sl company network) or X130 (828D) by default; the bind address is configured in /user/system/etc/opcua/opcua.cfg.

Does OPC UA read access slow down the NCK?

No, as long as subscriptions are configured with a reasonable publishing interval (200–500 ms for most NCK variables, 1000 ms for temperatures). The server caches the data internally; an excessive number of high-rate MonitoredItems can saturate the NCK-side buffer, but the default 100–200 node count per client is safe.

Where do I find the Create MyHMI /3GL documentation?

Siemens publishes the C++ and .NET programming manuals as attachments on the support portal. The latest publicly mirrored revisions are V04.08.02 of the release notes and the PDFs titled SINUMERIK Operate CPP and SINUMERIK Operate NET. Contact your Siemens sales representative for the licensed installer.

Back to blog