Problem Overview
The SIMATIC TP700 Comfort (6AV2 124-1GC01-0AX0) stores runtime data, audit trails, alarm logs, process value logs, and user-generated files (for example, PDF batch reports from a reporting function) on its SD card. The integrated logging mechanisms inside WinCC Comfort V14 allow you to redirect the standard logs to a network share through the "Logs" editor, but user-generated files such as PDFs are not covered by that path. The result: a partially synced SD card where the operator sees alarm logs on the server, but the batch reports still live on the removable media and disappear if the SD card is rotated.
This reference solves that gap. It documents a VBScript-based approach that copies the full contents of the SD card (or a filtered subset) to a configured UNC network folder, triggered either cyclically, on tag change, or directly after a new PDF is created. The solution runs entirely on the panel; no additional PC service is required.
Prerequisites
| Item | Requirement |
|---|---|
| HMI hardware | SIMATIC TP700 Comfort, firmware matching the TIA Portal V14 image (V14.0.0.x) |
| Engineering | TIA Portal V14 SP1 Update 6 or later, WinCC Comfort V14 |
| Storage | Siemens-approved SD card (for example, 6AV2 181-2AA10-0AA0, 2 GB or larger). Industrial SLC cards recommended for 24/7 operation |
| Network | Ethernet connection from the panel to the Windows file server. SMB 1.0/2.0/3.0 negotiated automatically by Windows |
| Server share | Windows share with read/write permission for the service account the panel uses (typically the panel's local Windows user when configured under "Network and Internet") |
| Runtime license | WinCC Comfort/ES V14 runtime license activated on the panel |
| Script runtime | No additional license - VBScript is part of the Comfort Panel runtime |
Understanding the TP700 Comfort File System
Three logical storage areas are exposed to VBScript on a Comfort Panel:
| Path constant | Physical location | Typical contents |
|---|---|---|
\Flash\ |
Internal NAND flash (project memory) | Compiled RT project, recipe DB, persistent tags |
\Storage Card SD\ |
Removable SD card slot X51 | Audit/alarm logs, exported recipes, batch PDFs, user files |
\Storage Card USB\ |
USB port X61 (front) | External backup, service files, USB stick for recipe transfer |
\Network\ |
Mounted network drives (when configured) | Direct UNC mount when persisted |
The VBScript FileSystemObject (FSO) model is fully available and accepts all standard methods. The runtime enforces case-insensitive paths, but the backslash convention is mandatory. Mixing forward and backward slashes is not permitted and will raise runtime error 5 (Invalid procedure call or argument).
Step 1 - Configure the Network Folder in the Panel
Open the panel project in TIA Portal V14 and configure the network share under Control Panel > Network and Dial-Up Connections > Network or, more commonly for runtime use, through the "Network Folder" entry in the project tree.
- Project tree → TP700 Comfort > Online & Diagnostics > Network Folder.
- Click Add and enter:
-
UNC path:
\\SERVERNAME\HMI_Backup -
User name:
HMIService(or your domain service account) - Password: the service account password
-
Domain:
YOURDOMAIN(or leave blank for local accounts)
-
UNC path:
- Tick Restore connection after restart so the share re-mounts on power-up.
- Transfer the project to the panel and confirm the share is visible in the panel's Control Panel > Network applet.
You can verify the mount from the runtime with the following VBScript (used in a button click for example):
Dim fso, drv
Set fso = CreateObject("Scripting.FileSystemObject")
If fso.FolderExists("\Storage Card SD\") Then
SmartTags("Status_NetFolder") = "SD OK"
End If
' Test UNC directly
If fso.FolderExists("\\\\SERVERNAME\\HMI_Backup") Then
SmartTags("Status_NetFolder") = "NET OK"
End If
"\\\\SERVER" in code becomes the runtime path \SERVER. In a tag or in HMI faceplates where the path is entered as a string tag value, use single backslashes.Step 2 - Create the Copy Routine
Create a new VBScript function in the project's Scripts > VB Scripts folder. Name it CopySDtoNetwork. The function below walks the SD card recursively and copies every file that does not already exist on the target share. New files only - existing files are not re-copied, so the function is idempotent and safe to call cyclically.
Function CopySDtoNetwork()
Dim fso, srcFolder, dstFolder, subFolders, file, subFolder
Dim srcPath, dstPath, errDesc
srcPath = "\Storage Card SD\"
dstPath = "\\SERVERNAME\HMI_Backup\TP700\"
Set fso = CreateObject("Scripting.FileSystemObject")
' --- Pre-checks ---
If Not fso.FolderExists(srcPath) Then
SmartTags("Status_Copy") = "ERR: SD missing"
CopySDtoNetwork = False
Exit Function
End If
If Not fso.FolderExists(dstPath) Then
On Error Resume Next
fso.CreateFolder(dstPath)
If Err.Number <> 0 Then
SmartTags("Status_Copy") = "ERR: " & Err.Description
CopySDtoNetwork = False
Exit Function
End If
On Error Goto 0
End If
Set srcFolder = fso.GetFolder(srcPath)
Set dstFolder = fso.GetFolder(dstPath)
' --- Copy root-level files ---
For Each file In srcFolder.Files
If Not fso.FileExists(dstFolder.Path & "\" & file.Name) Then
fso.CopyFile file.Path, dstFolder.Path & "\" & file.Name, False
End If
Next
' --- Recurse into subfolders ---
Set subFolders = srcFolder.SubFolders
For Each subFolder In subFolders
Dim newDst
newDst = dstFolder.Path & "\" & subFolder.Name
If Not fso.FolderExists(newDst) Then
fso.CreateFolder newDst
End If
CopyRecursive fso, subFolder, newDst
Next
SmartTags("Status_Copy") = "OK @ " & Time
SmartTags("LastCopyTimestamp") = Now
CopySDtoNetwork = True
End Function
Sub CopyRecursive(fso, src, dst)
Dim file, sub
For Each file In src.Files
If Not fso.FileExists(dst & "\" & file.Name) Then
fso.CopyFile file.Path, dst & "\" & file.Name, False
End If
Next
For Each sub In src.SubFolders
Dim newDst
newDst = dst & "\" & sub.Name
If Not fso.FolderExists(newDst) Then
fso.CreateFolder newDst
End If
CopyRecursive fso, sub, newDst
Next
End Sub
For the common case where only PDF batch reports are required, restrict the copy with a filter and copy just the matching files:
Function CopyPDFsOnly()
Dim fso, srcFolder, file, dstPath, baseName
Set fso = CreateObject("Scripting.FileSystemObject")
Set srcFolder = fso.GetFolder("\Storage Card SD\BatchReports")
dstPath = "\\SERVERNAME\HMI_Backup\BatchReports\"
If Not fso.FolderExists(dstPath) Then fso.CreateFolder(dstPath)
For Each file In srcFolder.Files
If LCase(Right(file.Name, 4)) = ".pdf" Then
baseName = dstPath & file.Name
If Not fso.FileExists(baseName) Then
fso.CopyFile file.Path, baseName, False
End If
End If
Next
SmartTags("Status_Copy") = "PDF sync done"
End Function
Step 3 - Trigger the Script
Comfort Panels offer four trigger mechanisms. Pick the one that matches the application.
| Trigger | Where configured | When it fires | Best for |
|---|---|---|---|
| Tag change | Tag properties → Events → Change value | When the configured tag changes value | Triggered by a tag set after a PDF is generated |
| Scheduled task | Scheduler → Add task → Trigger VBScript | Cyclic (e.g. every 60 s) or one-shot at a time | Generic periodic safety-net sync |
| Button / IO field | Event of the screen object | On operator action | Manual "Sync now" button |
| Alarm-acknowledged | Alarm class → Event | When a specific alarm is acked | Sync after a defined event |
For the original requirement - "copy every time a new PDF is created" - the recommended approach is to create an internal tag NewBatchReport in the PLC. In the function that creates the PDF on the panel, set SmartTags("NewBatchReport") = True. The tag's value-change event invokes CopyPDFsOnly. Reset the tag from the script once the copy succeeds.
A safety-net scheduler should still run CopySDtoNetwork every 15 minutes. This catches anything missed by the tag-triggered event (for example, if the panel rebooted during a batch).
Step 4 - Error Handling and Status Tags
WinCC VBScript on a Comfort Panel uses the standard VBScript error model. The runtime supports On Error Resume Next and Err.Number, but the script is not compiled - the editor catches only a subset of errors at design time. The following patterns are recommended for production code.
Sub SafeCopy(srcFile, dstFile)
On Error Resume Next
fso.CopyFile srcFile, dstFile, False
If Err.Number <> 0 Then
SmartTags("Status_Copy") = "ERR " & Err.Number & ": " & Err.Description
Err.Clear
End If
On Error Goto 0
End Sub
Map the most common runtime errors to operator-readable messages:
| Err.Number | Meaning | Likely cause | Remediation |
|---|---|---|---|
| 5 | Invalid procedure call or argument | Path with mixed slashes, or empty source path | Use only backslashes; verify path tag length |
| 52 | Bad file name or number | File handle exhausted or invalid path syntax | Close fso, verify UNC syntax with double backslashes in literals |
| 53 | File not found | Source file deleted between FolderExists and CopyFile | Wrap copy in On Error Resume Next; retry next cycle |
| 70 | Permission denied | Service account lacks write permission on share | Grant Modify on share + NTFS; verify in Control Panel |
| 76 | Path not found | Target folder missing, or share disconnected | Create folder with fso.CreateFolder; check network |
| 1004 | FSO method failed | Network timeout, share offline | Retry; check Windows firewall on server |
Step 5 - Transfer and Verify
- Compile the project: Project → Compile → Software (rebuild all).
- Download to the panel: Online → Download to device → TP700 Comfort.
- On the panel, open Control Panel → Service → Script Debugger (if enabled) to step through the copy routine on first run.
- Create a test file on the SD card:
Dim fso Set fso = CreateObject("Scripting.FileSystemObject") fso.CreateTextFile "\Storage Card SD\TESTFILE.txt", True fso.OpenTextFile("\Storage Card SD\TESTFILE.txt", 2).WriteLine "Hello " & Now - Trigger the script. Verify the file appears on the share within a few seconds. The file's timestamp on the server should match the runtime clock of the panel.
- Open the panel's Event Viewer → Custom Logs → WinCC to confirm no script errors are logged.
Performance and Sizing
The TP700 Comfort has a 600 MHz ARM Cortex-A8 and limited write endurance on the internal flash. The script should not be called more often than necessary. Recommended tuning values:
| Parameter | Recommended | Rationale |
|---|---|---|
| Scheduler cycle | 15 min for full SD copy; 60 s for PDF-only copy | Limits SD write amplification |
| Max file size to copy | < 50 MB per file | Avoids blocking the panel for >5 s during a single copy |
| Skip-on-exist logic | Always enabled | Idempotent; safe to re-run |
| Recursion depth | <= 8 levels | VBScript stack limit ~400 frames; recursion depth is rarely an issue, but defensive coding is cheap |
| Folder name on share | \SERVER\HMI_Backup\TP700\ |
Allows multiple panels to share one folder; the per-panel subfolder avoids name collisions |
Alternative: Using the "Network Drive" Approach
As an alternative to scripting, mount the share as a persistent network drive on the panel and have the standard logging mechanisms (audit trail, alarm log, process value log) write directly to it. The logs are configured under Project tree → HMI → Logs → [log name] → Storage location → Network drive. This handles the structured data but does not cover the user's PDFs - the VBScript path is still required for that case.
If the application only needs the standard logs, the network drive approach is preferred: it is faster, native, and survives a power-cycle without scripting state issues. The two approaches are complementary and can be combined in one project.
Troubleshooting Matrix
| Symptom | Probable cause | Diagnostic step | Fix |
|---|---|---|---|
| Status_Copy = "ERR: SD missing" | SD card not inserted or corrupted | Control Panel → Storage Devices | Re-seat or replace SD card; re-format FAT32 |
| Status_Copy = "ERR: Path not found" | UNC share not reachable | Ping server from panel command shell | Verify DNS, route, firewall (TCP 445) |
| Status_Copy = "ERR: Permission denied" | Service account lacks write | Map share from a Windows PC with same account | Grant Modify permission; check share ACL |
| Script does not fire | Event not linked to the script | Open Scheduler / Tag events, verify the function name is selected | Re-link the event to CopyPDFsOnly or CopySDtoNetwork
|
| Files copied but truncated | Network timeout or share full | Check free space on server; check event log for 1004 errors | Increase disk quota; retry with back-off |
| One file is never copied | Filename contains unicode not in target codepage | Check file name on SD vs server codepage | Rename file or change system locale on the panel |
| Periodic copy slows the HMI | Scheduler cycle too short for the file set | Measure copy duration with timestamp diff | Reduce copy frequency or split into two passes (PDFs only first, full sync every hour) |
Best Practices and Field-Notes
- Keep a local copy first. The SD card is the source of truth. The network copy is a backup. Always copy from SD to network, never the other way around, to avoid corrupting active logs.
-
Use the
OverwriteFiles = Falseflag in theCopyFilecall. If the operator has edited a backup on the server, the script should not silently overwrite it. - Persist the last-sync timestamp in a recipe or a retentive tag. After a panel reboot you can immediately see how stale the backup is.
- Disable SMB 1.0 on the Windows server if possible. Comfort Panels negotiate SMB 2.0/3.0 transparently. SMB 1.0 is a security risk and is not required.
- Log the script results to a custom CSV on the SD card itself. This gives you a forensic trail if the network copy silently fails for weeks.
- Avoid long-running copies in tag-change events. If the copy takes more than 1 second, prefer the scheduler, which runs in its own thread.
Related Siemens Documentation
- SIMATIC HMI Comfort Panels Operating Instructions
- WinCC Comfort V14 Scripting Manual (VBScript Reference)
- TIA Portal Help: Logs and data storage
- Comfort Panel: Configuring a network folder
- WinCC V14 SP1: Project transfer and backup
Why does my alarm log go to the network share but my PDF does not?
Alarm, audit, and process-value logs are handled by the internal WinCC logging engine, which has a configurable storage path that accepts a UNC target. PDF batch reports are arbitrary user files, so they fall outside the logging engine and require a VBScript-based copy routine using the FileSystemObject.
What is the exact UNC path format from a VBScript string literal?
Inside a VBScript string literal, every backslash must be escaped, so the UNC path appears as "\\\\SERVERNAME\\HMI_Backup" in code, which the runtime resolves to \\SERVERNAME\HMI_Backup. In a string tag, use single backslashes: \\SERVERNAME\HMI_Backup.
Can the script run in the background without a logged-in user?
How do I avoid copying the same file repeatedly?
Check fso.FileExists on the destination before calling CopyFile, or use a manifest of filenames copied during the previous cycle. For a true delta sync, compare file.DateLastModified with a stored value in a recipe and skip when equal.
Is the same VBScript valid on a Unified Comfort Panel (MTP/MTP Unified)?
No. Unified Panels use JavaScript and a different API. The WinCC Unified equivalent is HMIRuntime.FileSystem with async methods. Migrate the VBScript to JavaScript and adopt promises or async/await for the file operations.