SINUMERIK 840D SL TCU Alarm Log Backup and Diagnostic Export

David Krause13 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

SINUMERIK 840D SL TCU Alarm Log Retention, Backup, and Diagnostic Export

When an NCK reset or an uncontrolled power-down is performed on a SINUMERIK 840D sl machine, the active alarm log disappears from the operator panel. This behavior is not a fault - it is the documented design of the TCU 30.3 when the system is delivered with a CompactFlash card only. The following reference consolidates the underlying storage architecture, the limits of the TCU 30.3 service menu, and the approved procedures to capture alarm and diagnostic data to a USB stick or to a remote syslog server.

Field impact: Without a persistent log, post-mortem analysis of trip events and intermittent alarms is impossible. Service engineers must select one of the three documented capture paths (HDD retrofit, remote syslog, or scripted dump) before the next trip occurs.

1. Problem Statement

On SINUMERIK 840D sl systems equipped with a TCU 30.3 and no hard disk, the following symptoms are reported from the field:

  • Alarm log entries visible in the HMI disappear after NCK reset, NCK power-on reset, or a hard power cycle.
  • The PLC alarm buffer is preserved (the PLC retains power for its backup interval), but the NCK alarm buffer is volatile.
  • Diagnostic files generated with the key sequence Ctrl+Alt+D land on the connected USB stick only at the moment the key is pressed; nothing is written automatically in the background.
  • The internal CF card (typically 1 GB on TCU 30.3) does not retain the alarm log across reset, and is too small to host a continuous logger.

The recurring question from commissioning engineers is: can the alarm log be copied to a USB stick automatically, without operator intervention? The short answer is: only if the storage media is upgraded to a hard disk, or a remote syslog receiver is configured, or an external automation triggers the diagnostic dump on every event.

2. Alarm Log Storage Architecture on 840D sl

The SINUMERIK 840D sl separates alarm storage across three independent domains. Understanding which domain holds which alarm class is the prerequisite to designing a retention strategy.

Domain Physical location Volatility Cleared by
NCK alarm buffer NCK volatile RAM (NVRAM mirror on CF card) Volatile - purged on NCK reset NCK reset, warm restart, power loss longer than PLC backup time
PLC alarm buffer PLC RAM, battery-backed SRAM Non-volatile while PLC backup is healthy PLC stop, MRES, expired battery, STOP-to-RUN transition if non-retentive
HMI / TCU log TCU file system, primarily /var/log Non-volatile while CF card is healthy Manual clear, TCU reinstallation, log rotation
Remote syslog External syslog server (UDP/TCP 514) Depends on server retention policy Server-side rotation, manual delete

The TCU 30.3 is a Linux-based thin client. Its /var/log/messages file collects HMI boot, network, NCU-PLC handshake, and TCU service messages. NCK alarms themselves are not written to the TCU local file system in the default configuration - they live in NCK memory. The TCU can only display them while the NCK is alive and the HMI-to-NCK link is up.

3. Root Cause: Why the Log Disappears

The root cause is the combination of four documented design constraints:

  1. NCK alarm storage is volatile. Each NCK reset clears the in-RAM alarm buffer; only the active alarm text and the last clear-event survive the boot phase.
  2. The NVRAM mirror on the CF card is reserved for machine data, tool data, R variables, and settable frames. It is not sized for full alarm-log retention.
  3. The 1 GB CF card shipped with most TCU 30.3 systems is provisioned for the HMI software image, runtime files, and OEM add-ons. The user-writeable persistent partition is essentially zero.
  4. The Ctrl+Alt+D service action is a one-shot dump tool. It is not a continuous logger and was never intended to operate as such.

To persist the alarm log, one of three methods must be put in place: an HDD on the PCU/TCU, a remote syslog receiver on the plant network, or an external automation that triggers the Ctrl+Alt+D sequence on every event.

4. TCU 30.3 Local Log File Menu

The SINUMERIK 840D sl TCU 30.3 Equipment Manual (Siemens, 05/2019) describes the service menu that exposes the local log file viewer. The procedure is the same on HMI Operate 4.5 SP2 and later.

  1. Press the Menu key on the operator panel and navigate to Setup > Service.
  2. Enter the service password. The OEM default is SUNRISE for SINUMERIK Operate; the OEM may override this with their own password.
  3. Open TCU menu > Local log file.
  4. Two options are available:
    • Show local log file - displays the TCU's own syslog output (HMI boot, network, errors, NCK-PLC handshake messages).
    • Show log file of remote devices - fetches and displays the syslog stream of other devices visible to the TCU (NCU, additional TCUs, network components that have been configured to forward syslog).

This viewer is read-only. It does not export; it shows the rolling log buffer. To capture the log to a file, use one of the procedures in section 5.

5. Approved Solutions to Persist Alarm Data

There is no single toggle to make the alarm log survive an NCK reset on a CF-only system. The four field-proven solutions are described below; choose the one that matches the machine's hardware configuration.

5.1 Manual USB Dump (Default Method)

This procedure is built into every TCU 30.3 system. It collects the NCK alarm history, the PLC diagnostic buffer, the HMI log files, and the active configuration into a timestamped folder on a USB stick.

  1. Insert a USB stick (FAT32 file system, minimum 4 GB free) into the TCU's front USB port. NTFS and exFAT are not supported on TCU 30.3.
  2. Click on the HMI surface to ensure the focus is on the operator panel, not a remote desktop or service window.
  3. Press and hold Ctrl+Alt+D simultaneously for approximately 2 seconds.
  4. The HMI shows a progress bar while the system snapshots the following data:
    • NCK alarm log and clear alarms
    • PLC diagnostic buffer (S7 diagnostic buffer equivalent)
    • System logs (/var/log)
    • NC and drive machine data (MD) snapshot
    • Active compensation data (leadscrew error compensation, sag compensation)
    • Trace recordings if a trace session is open
  5. On completion, a folder /Diagnostic_Data/<YYYY-MM-DD_HH-MM-SS>/ is created on the USB stick. The dialog "Diagnostic data saved" confirms success.

This method is one-shot. To capture the log at the moment of a trip, the operator must be present, or an automation (PLC script or HMI script) must generate the key sequence. See section 5.4 for a non-standard automation approach.

5.2 Syslog Forwarding to a Remote Server

Syslog forwarding is the only way to achieve continuous, automatic, NCK-reset-proof alarm capture without installing an HDD. The TCU 30.3 supports the standard Linux syslogd and syslog-ng remote-logging features.

  1. Assign a static IP to the TCU in the Setup > Network menu. DHCP works but makes log correlation harder when the lease changes.
  2. Open an SSH session to the TCU (default user manufact, OEM password) or mount a USB stick and edit the configuration file directly.
  3. Edit /etc/syslog-ng/syslog-ng.conf (the file path varies with HMI version; older versions use /etc/syslog.conf).
  4. Add a destination entry for the remote syslog server:
    destination d_remote {
        udp("192.168.1.100" port(514));
    };
    log {
        source(s_src);
        destination(d_remote);
    };
  5. Reload syslog: systemctl reload syslog-ng (or reboot the TCU if the service manager is not accessible).
  6. On the syslog server (e.g., syslog-ng, rsyslog, or Kiwi Syslog), create a filter that captures facility.local0 through local7 and assigns a dedicated file per TCU.

NCK alarms are forwarded to the HMI as PLC-style alarm events; the HMI software converts them to syslog messages tagged with the alarm number and clear time. The remote log survives an NCK reset because it is written to a file on a separate host. For redundancy, configure two remote targets and prefer TCP 514 over UDP where the HMI version supports RFC 5424.

5.3 Hard-Disk Upgrade on the PCU

For new installations, the cleanest solution is to replace the CF-only PCU with a hard-disk-based PCU (PCU 50.3 or later, with HDD option). On HDD-equipped systems, the HMI creates a rolling archive of alarm logs in /user/sinumerik/hmi/log/alarm_log/. Each file is named with its date and is rotated weekly. No operator action is required.

Storage media Capacity Continuous log? Survives NCK reset? Min. HMI version
CF card (1 GB, TCU 30.3 default) ~1 GB No (HMI uses full image) No All
CF card (4 GB, PCU 50.3) 4 GB Limited No HMI Operate 4.5+
HDD (PCU 50.3 + HDD option) 250 GB and up Yes (rolling) Yes HMI Operate 4.5+
SSD (PCU 50.5 + SSD option) 240 GB and up Yes (rolling) Yes HMI Operate 4.7+

Retrofitting an HDD into an existing CF-only TCU is not officially supported by Siemens; the supported path is a hardware replacement of the PCU. Verify availability of the HDD/SSD option in the SINUMERIK 840D sl catalog before ordering.

5.4 PLC-Triggered Automatic Dump

Where the machine builder wants an "automatic USB capture on every alarm" without changing storage media, the standard approach is to program the PLC to drive the diagnostic dump on an alarm-edge condition.

  1. Add an FB in the PLC that monitors DB1900.DBB0 (HMI status) and a configured list of NCK alarm numbers from DB1600 / DB1601.
  2. On detection of a new alarm, the FB activates a digital output wired to a small embedded controller (e.g., S7-1200 or a Raspberry Pi with USB relay) that simulates the Ctrl+Alt+D keypress via a USB-HID device.
  3. The HMI writes the dump to the USB stick mounted on the controller.

This is a non-standard integration; it is documented here for completeness but is not part of the Siemens product line. Validate against the machine's functional safety requirements before deploying.

6. Step-by-Step: Capturing the Diagnostic Data to USB (Field Procedure)

The following procedure is the recommended service action when an alarm is reported and the operator is unable to describe the conditions leading up to it.

  1. Confirm the HMI version: Menu > Setup > General > HMI version. Required: SINUMERIK Operate 4.5 SP2 or later for full content. Earlier versions still produce a dump, but some MD files are omitted and the alarm-log format is older.
  2. Insert a USB stick (FAT32, at least 4 GB free) into the front USB port of the TCU.
  3. Press and hold Ctrl+Alt+D until the HMI displays "Diagnostic data is being saved".
  4. Wait for the confirmation dialog "Save completed". Typical duration: 30 s to 3 min depending on HMI version and number of active machine data items.
  5. Remove the USB stick. Mount it on a service PC and verify the folder Diagnostic_Data/<timestamp>/ contains the following files:
    • alarm_log.txt - the active alarm history with timestamp, alarm number, and clear time
    • md_dump.txt - all NC machine data
    • plc_diag_buffer.bin - PLC S7 diagnostic buffer (open in STEP 7 / TIA Portal)
    • drive_trace/ - SINAMICS trace if enabled
    • hmi.log - TCU syslog
  6. Compress the folder and attach it to the service ticket. Do not edit the files before sending - byte counts and timestamps are part of the diagnostic value.

7. Verification

After applying any of the solutions above, verify the alarm capture is working with the following tests. All four checks should pass before the system is returned to production.

Check Expected result Method
Local log file visibility TCU menu > Local log file shows the HMI syslog Section 4 procedure
USB dump integrity All five files present and non-empty Section 6 step 5
Syslog receipt (remote) Test message visible on the remote server within 1 s logger "test" from the TCU shell
Survives NCK reset Alarm log present after warm restart Trigger alarm, reset NCK, inspect remote syslog
PLC buffer intact PLC diagnostic buffer preserved Trigger alarm, observe PLC LED / STEP 7 diagnostic buffer

8. Troubleshooting Matrix

Symptom Likely cause Corrective action
Ctrl+Alt+D has no effect HMI focus is on a non-OP window (e.g., a remote desktop) Click on the HMI surface first, then press the key sequence
USB stick not detected USB stick is NTFS or exFAT, or formatted by a non-Windows tool with a non-standard MBR Reformat to FAT32 on a Windows PC; verify with fsck if Linux is available
Dump file is empty No active alarm; PLC and NCK were clean at dump time Trigger a known alarm first (e.g., NCK 21612 by opening the door during AUTO) and re-dump
Syslog messages not received Firewall blocks UDP 514; routing issue Open UDP 514 between TCU and syslog server; verify with tcpdump -i eth0 port 514
TCU 30.3 menu "Local log file" greyed out Service password not set or not entered Enter service password; OEM default SUNRISE
Alarm log clears on reset despite HDD installed HDD not formatted; HMI installed on CF only Re-image the PCU with the HDD as the boot device; verify in Setup > General > Memory
Remote log file viewer shows no entries Other device does not forward syslog to TCU Configure syslog on the remote device; verify port and protocol match the TCU listener
Dump folder is created but files are 0 bytes USB stick removed before completion, or write-protected Re-run the dump; wait for the "Save completed" dialog; check the write-protect tab on the USB stick

9. Specifications and Parameters

Parameter Value
TCU 30.3 operating system Embedded Linux (SUSE-based, slimmed)
Default syslog port UDP 514 (RFC 5424 over TCP 514 supported on Operate 4.7+)
Diagnostic dump key sequence Ctrl + Alt + D (hold 2 s)
Supported USB file system FAT32 only
Default service password (Operate) SUNRISE (OEM may override)
NCK alarm buffer size 64 entries (standard), expandable with MD settings
PLC diagnostic buffer size 100 entries (S7-300/400 compatible)
Default service menu access Menu > Setup > Service > TCU menu > Local log file
Recommended syslog redundancy Two remote targets; TCP 514 plus TLS where supported
Specification note: The values above are typical for HMI Operate 4.5 SP2 and later. Confirm against the active HMI version's release notes when the system is on a non-current service pack.

10. Field Commissioning Checklist

Use the following checklist during commissioning or after a hardware swap to confirm the alarm-log retention strategy is in place.

  1. Identify the storage media (CF card, HDD, SSD) and the HMI version installed.
  2. If CF card only: confirm the operator is trained on the Ctrl+Alt+D procedure and that a USB stick is mounted in a known location.
  3. If HDD/SSD: confirm the alarm-log directory /user/sinumerik/hmi/log/alarm_log/ is populated after a controlled NCK reset.
  4. If syslog is enabled: confirm the remote server is receiving local0 through local7 messages from the TCU.
  5. Run a controlled test by triggering a non-fatal alarm (e.g., 21612 with door open during AUTO in a safe state) and verify the alarm appears in the chosen retention path within 5 s.
  6. Record the chosen retention path, the responsible engineer, and the review interval in the maintenance log.

Why is the alarm log cleared after an NCK reset on a SINUMERIK 840D sl?

The NCK alarm buffer lives in volatile RAM. On NCK reset or a power loss longer than the PLC backup time, the buffer is purged. Persistent retention requires an HDD/SSD on the PCU, a remote syslog server, or a manual dump via Ctrl+Alt+D before the reset.

Can the alarm log be written automatically to a USB stick?

No, not on a TCU 30.3 with CF card only. The HMI does not contain a background service that streams NCK alarms to a mounted USB device. The only automatic persistent capture is via syslog forwarding to a remote server, or by retrofitting an HDD/SSD in a PCU 50.3 or newer.

Where on the TCU 30.3 can I view the local log file?

Open Menu > Setup > Service > TCU menu > Local log file. Two options are available: "Show local log file" for the TCU's own syslog and "Show log file of remote devices" for syslog streams from other network devices. See the SINUMERIK 840D sl TCU 30.3 Equipment Manual for menu paths.

What does the key sequence Ctrl+Alt+D actually do?

It triggers a one-shot diagnostic dump. The HMI writes the NCK alarm log, PLC diagnostic buffer, machine data, drive traces, and the HMI syslog into a timestamped folder on the inserted USB stick. The action takes 30 s to 3 min and must be performed manually each time.

Is a 1 GB CF card sufficient for continuous alarm logging?

No. The 1 GB CF card is provisioned for the HMI runtime image and leaves essentially no writable space for log files. Continuous logging requires either a remote syslog server or an HDD/SSD-equipped PCU (PCU 50.3 or later).

Which file system must the USB stick use for the diagnostic dump?

FAT32 only. NTFS and exFAT are not supported on the TCU 30.3 front USB port. Reformat the stick to FAT32 on a Windows PC before use, and avoid sticks larger than 32 GB unless reformatted with a third-party tool.

Back to blog