WinAC RTX Retain Data Loss on Power Cycle: Troubleshooting

David Krause17 min read
Other TopicSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: WinAC RTX Retain Variable Persistence

Siemens WinAC RTX (Windows Automation Center Real-Time eXtension) is a software PLC that executes STEP 7 programs on a Windows-based industrial PC rather than on a dedicated hardware CPU such as the SIMATIC S7-300 or S7-400. Unlike a hardware PLC, which retains remanent data through internal battery-backed SRAM, non-volatile FRAM, or MMC (Micro Memory Card) persistence, WinAC RTX stores its retain area in the host PC's working memory. Power loss therefore requires a coordinated shutdown sequence to flush that memory to a persistence file on disk before the Windows host is de-energized.

The RETAIN attribute on a STAT variable in STEP 7 / SIMATIC Manager only marks the tag as eligible for the retention mechanism; it does not by itself guarantee survival of an uncontrolled power loss. Engineers familiar with the S7-300 expect the Retain checkbox to provide identical behavior to a hardware CPU where remanent data is preserved across a power cycle. On WinAC RTX, that expectation is incorrect without additional infrastructure.

A successful retain implementation on WinAC RTX requires three coordinated components:

  1. A non-volatile media (HDD, SSD, or industrial CFast) for the persistence file.
  2. An early warning of impending power failure delivered to the WinLC runtime.
  3. A controlled shutdown path that allows the WinLC runtime to serialize its retain area to disk before the operating system loses power.

This article covers the root cause of the typical "retain lost on power cycle, but preserved on Windows restart" symptom, and provides four field-proven solutions with commissioning and verification steps.

Retain Behavior Comparison: S7-300 vs WinAC RTX

The diagnostic value of the symptom "retain lost on power cycle, but preserved on a Windows restart" becomes clear when the two retention models are compared side by side.

Property SIMATIC S7-300 / S7-400 WinAC RTX (WinLC)
Retain storage media Battery-backed SRAM, FRAM, or MMC Host PC RAM, written to disk on shutdown
Time to persist data Always powered (battery) Milliseconds to seconds during shutdown
Power loss detection Hardware buffer / supercap Requires PowerLoss signal or UPS event
Action on power loss CPU continues from buffered energy or restarts with retained data intact Runtime must be told to stop, persist, and exit before Windows halts
RETAIN bit in STEP 7 Marks tag as remanent; backed by hardware Marks tag as retain; only persisted if WinLC is given a graceful shutdown window

The fact that data survives a Windows restart (user-initiated Start > Restart) confirms the retain mechanism itself is correctly configured: the WinLC runtime executes its SaveRetainData() path during normal stop, and the values land on disk. The failure on power cycle confirms that the runtime never had the chance to run that save path because the host lost power without a prior shutdown trigger.

Problem Description

Observed symptoms in a typical WinAC RTX deployment:

  • All STAT variables marked with the Retain attribute in the STEP 7 symbol table or DB editor reset to their default initial values after an uncontrolled mains power loss.
  • The same variables retain their values across a Windows restart triggered from the Start menu or by an shutdown /r command.
  • WinCC, WinCC flexible, or third-party HMI running on the same PC sees the tags revert to defaults, producing recipe loss, counter resets, and state-machine corruption on the next OB1 scan.
  • The WinLC service is configured for Autostart on boot; OB100 (warm restart) and OB101 (hot restart) do not find valid retain data to restore.

This is the canonical signature of missing PowerLoss notification to the WinAC RTX runtime, not a bug in STEP 7 retain configuration.

Root Cause: The PowerLoss Signal

WinAC RTX distinguishes between three shutdown classes, and the difference matters:

Shutdown class Trigger Retain data saved?
Controlled stop (e.g. WinLC stop from SIMATIC Manager) Operator or HMI command Yes - WinLC flushes retain to disk
Windows shutdown / restart OS-initiated stop Yes - OS triggers WinLC stop via service control
Uncontrolled power loss Mains removed, battery exhausted No - runtime never receives a stop event

To convert an uncontrolled power loss into a controlled stop, the WinAC RTX runtime must receive a PowerLoss signal in time to:

  1. Finish the current OB1 cycle.
  2. Execute OB80 / OB121 / OB122 error handling if needed.
  3. Run internal retain-save routine to disk (typically %ProgramData%\Siemens\Automation\WinAC\Retain\*.dat or installation-specific path).
  4. Signal the Windows service control manager to stop the PC.

The buffer time required is typically 5 to 30 seconds depending on program size, number of retain tags, and disk write speed. This buffer is delivered by either:

  • A Siemens SIMATIC IPC whose BIOS and power supply expose a PowerFail signal (often via the SIMATIC motherboard monitoring ASIC to WinAC RTX over a Siemens-proprietary interface or a configured GPIO).
  • An external UPS (SITOP DC UPS recommended) whose monitoring software triggers WinLC_Shutdown.exe when battery capacity drops below a threshold.

System Architecture: Properly Buffered WinAC RTX

24 V DC PSU Industrial Mains Mains fail detected SITOP DC UPS 6EP1931-2DC / UPS1600 Battery buffer 5-30 s SIMATIC IPC WinAC RTX + WinLC PC power input SITOP UPS Manager USB / Serial / PROFINET Triggers script on low battery Calls WinLC_Shutdown.exe WinAC RTX Runtime WinLC service OB1 / Retain save path Writes retain.dat, stops PC Uncontrolled mains loss = retain corruption if buffer is absent

Diagnostic Procedure

Before changing configuration, run the following checks in order. Each one isolates one variable in the failure chain.

  1. Confirm the host PC is not a Siemens IPC with a documented PowerLoss output. Open Device Manager, expand System devices, and look for a SIMATIC or Siemens watchdog / power management device. If present, the BIOS / WinAC configuration tool should expose the PowerLoss pin; consult the IPC manual for the specific SKU. If not present, the IPC is not signalling WinAC, and a UPS solution is mandatory.
  2. Verify the retain configuration in STEP 7. In SIMATIC Manager, open the S7 program, right-click the DB or the symbol containing the STAT, and confirm the Retain column shows a check mark in the symbol table for the affected tags. For an S7-compatible WinAC project the retain mask is also visible under Properties > Retain.
  3. Inspect the persistence path on disk. After a clean Windows restart (where retain does survive), navigate to the WinAC retain data folder (default C:\ProgramData\Siemens\Automation\WinAC or the path selected during WinAC RTX setup). Confirm files with extensions .rdb, .dat, or *.bina are written and have recent modification times. If they are present, the save path itself is healthy.
  4. Test the UPS path. With a SITOP DC UPS (or equivalent) installed, pull the mains plug. Watch the SITOP UPS Manager (or the equivalent monitoring tool) and confirm WinLC_Shutdown.exe is invoked within the configured threshold. The IPC should then perform an orderly Windows shutdown, and the retain values should be present on the next power-up.
  5. Inspect the Event Log. After a failure, look under Windows Logs > Application for entries from WinLC, S7wnresx, or the SITOP UPS service. Error code 0x80070005 (access denied), 0x80004005 (unspecified), or simply a missing WinLC stop event before OS halt confirms the runtime never received a shutdown instruction.

Solution A: Siemens IPC with PowerLoss Signaling

On supported SIMATIC IPCs (e.g. SIMATIC IPC227G, IPC277G, IPC427G, IPC647E, IPC847E) the on-board power supply and BIOS expose a PowerFail signal that WinAC RTX can subscribe to. In this configuration, the IPC itself is the buffer: its internal hold-up time plus any installed UPS module is sized so that WinAC RTX receives a controlled stop notification through the IPC interface, persists its retain data, and then triggers Windows shutdown.

Commissioning steps:

  1. In BIOS, enable the Power Failure or PowerGood interrupt if it is exposed and confirm WinAC RTX is the consumer (not a third-party management agent).
  2. Install the SIMATIC IPC driver and management components shipped with the IPC; on modern IPCs this is the SIMATIC IPC DiagBase / SIMATIC IPC Configuration Center package.
  3. In the WinAC RTX configuration tool (Start > Siemens Automation > WinAC RTX > WinAC Config), set the PowerLoss source to SIMATIC IPC or the equivalent local enumerator.
  4. Set the hold-up time in the IPC BIOS to a value that gives the WinLC service a minimum of 10 s to flush retain data; 20 s is a safe default for typical programs of up to a few hundred retain tags.
Note: The exact BIOS label, register name, and configuration tool vary by IPC generation. Always cross-check the IPC's operator manual and the WinAC RTX readme for the firmware / build pair you are using.

Solution B: SITOP DC UPS with WinLC_Shutdown.exe

For non-Siemens IPCs (Dell, Advantech, Beckhoff, Kontron, etc.) the recommended Siemens-supported path is a SITOP DC UPS module buffering the 24 V rail, paired with the SITOP UPS Manager software that calls WinLC_Shutdown.exe on low-battery threshold. This is the architecture described in Siemens Support Entry 31410254 - Preventing loss of retained data with SITOP DC UPS and WinAC RTX.

Hardware components

Component Role Example SKU
24 V DC industrial PSU Mains conversion SITOP PSU8200 / PSU100
SITOP DC UPS module Bridging module with battery 6EP1931-2DC, 6EP1931-2EC, SITOP UPS1600
Energy storage Lead-acid or LiFePO4 buffer SITOP UPS500 series battery modules
IPC host Runs WinAC RTX + UPS Manager Any x86 IPC with USB or PROFINET

Software components

  • SITOP UPS Manager (part of the SITOP DC UPS toolset) - monitors the UPS state, exposes battery state, and triggers actions on thresholds.
  • WinLC_Shutdown.exe - WinAC RTX utility that performs an orderly WinLC stop and a Windows shutdown. Typical path: C:\Program Files\Siemens\Automation\WinAC RTX\WinLC_Shutdown.exe. Run with elevated privileges.

Commissioning steps

  1. Install the SITOP DC UPS module between the 24 V supply and the IPC's 24 V input. Verify polarity and the recommended wire cross-section from the UPS manual.
  2. Connect the SITOP UPS module to the IPC via USB (classic SITOP DC UPS) or PROFINET (SITOP UPS1600). The PROFINET variant is preferred on PROFINET-native WinAC RTX installations because the integration is documented in TIA Portal / STEP 7.
  3. Install the SITOP UPS Manager. Configure the COM port or PROFINET device matching the hardware.
  4. Set the battery low threshold to a value that gives at least 20 s of hold-up at the IPC's worst-case load. Lead-acid SITOP modules typically derate 30 to 50% at cold temperatures - derate the threshold accordingly.
  5. In SITOP UPS Manager, configure the action on battery low: run WinLC_Shutdown.exe /shutdown (or the documented flag set in the help). The action must be set to Run program, not just Log.
  6. Perform a controlled mains-loss test: with the program in RUN, pull the 24 V input to the SITOP DC UPS module. Verify in the SITOP UPS Manager log that the script fired, that WinLC transitioned to STOP, and that the IPC shut down within the configured window.
  7. Restore mains, restart the IPC, and verify that the retain values match the pre-power-loss state.
Note: The exact flags accepted by WinLC_Shutdown.exe differ between WinAC RTX 2008, 2010, and 2010 SPx. Read the help (WinLC_Shutdown.exe /? or the help bundled with the WinAC RTX installation) for the version installed on the host before scripting around it.

Solution C: Third-Party UPS with Windows Shutdown Script

When a non-Siemens UPS is already installed (APC, Eaton, Vertiv, CyberPower, generic USB HID UPS), the same idea applies: when the UPS signals "on battery low", Windows must run a script that stops WinLC and shuts down the host. The Windows mechanism for "scripts that run at shutdown" is a Group Policy shutdown script, configured through gpedit.msc on Windows Pro / Enterprise, or Group Policy Management on domain-joined machines.

The shutdown script must do three things, in order:

  1. Stop the WinLC service gracefully, which is what triggers the retain-data save path. The command is typically net stop "S7WinLC" (the exact service name depends on the WinAC RTX version - check services.msc). On WinAC RTX 2010 and later the service name is usually WinLC or S7WinLC.
  2. Wait for the service to reach the STOPPED state with a timeout. A 30 s timeout is typical.
  3. Initiate Windows shutdown with shutdown /s /t 0 /f or call WinLC_Shutdown.exe if present, which performs both steps internally.

A robust batch file C:\Scripts\winac_shutdown.bat typically looks like:

@echo off
rem Stop WinLC to flush retain data
net stop "S7WinLC" /y
timeout /t 5 /nobreak >nul
rem Verify stop; force-kill if still running after 30s
sc query "S7WinLC" | find "STOPPED" >nul
if errorlevel 1 (
  timeout /t 30 /nobreak >nul
  taskkill /f /im WinLC.exe
)
rem Shutdown Windows
shutdown /s /t 0 /f /c "UPS battery low - WinAC controlled shutdown"

For higher reliability on systems where the UPS-to-host signal may be missed, layer two triggers:

  1. The UPS vendor's power-chute / IPP / Network Card software, which monitors battery state and calls the same batch file on battery low.
  2. A Windows Task Scheduler task bound to Event ID 1 in the System log from source UPS, as a fallback path.

Configuring a Group Policy Shutdown Script

  1. Open gpedit.msc (Group Policy Editor). On Windows Pro / Enterprise this is bundled; on Windows Home it is not present and the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ShutdownWithoutLogon and the Scripts registry path must be used as fallback.
  2. Navigate to Computer Configuration > Windows Settings > Scripts (Startup / Shutdown).
  3. Double-click Shutdown in the right pane.
  4. Click Add, then Browse to the batch file created in Solution C. Windows does not pass parameters to shutdown scripts in this path; the script must be self-contained.
  5. Click OK and force a policy refresh with gpupdate /force from an elevated command prompt.
  6. Verify by running gpresult /r and confirming the script is listed under Applied Group Policy Objects > Scripts.
Note: The original Siemens FAQ 31410254 referenced Windows XP-era Group Policy behavior. On Windows 7 x32, Windows 10, and Windows 11, shutdown scripts configured through Computer Configuration run with system privileges by default, which is the correct context for stopping the WinLC service. If the script is configured under User Configuration instead, it runs as the logged-in user and may fail to stop the service due to ACLs.

Solution D: Windows Task Scheduler with UPS Event

When the UPS vendor does not provide a clean "battery low" hook, a Windows Task Scheduler task can monitor the event log and fire the same shutdown script. Steps:

  1. Open taskschd.msc.
  2. Create Task (not Basic Task) with Run whether user is logged on or not and Run with highest privileges.
  3. Trigger: On an event > Custom > New Event Filter > By source: UPS, Event ID: 1 (or the ID documented by your UPS vendor for low battery).
  4. Action: Start a program > C:\Scripts\winac_shutdown.bat.
  5. Conditions: leave Start the task only if the computer is on AC power unchecked - we explicitly want the task to fire when AC is gone.

This layered trigger is the practical answer to the original question "how do I start WinLC_Shutdown.exe when the UPS battery is low?"

SITOP UPS Manager Configuration Reference

Parameter Typical value Notes
COM port / PROFINET device COM1, COM3, or detected PROFINET station Match to physical connection
Battery low threshold 20-30% of nominal capacity Must allow 20 s hold-up at worst-case load
Action on battery low Run program: WinLC_Shutdown.exe Test with a no-load test first
Action on mains return None, or power on IPC if BIOS supports Set per plant policy
Log verbosity Debug during commissioning, Info in production Debug writes to disk
Heartbeat to PC 5 s Shorter = faster detection, more load on host

Power Loss Timing Sequence

Mains FAIL t=0s SITOP UPS Buffering 5-30 s WinLC Save retain Windows Shutdown

Verification Procedure

Run these checks after any retain-related configuration change. Each is binary - it passes or it fails the retain pipeline.

  1. Static check: open SIMATIC Manager, recompile the S7 program, and confirm no warnings about unretained tags where retain is expected.
  2. Disk check: confirm the retain persistence files exist and have a recent modification timestamp after a clean Windows restart.
  3. Controlled-shutdown simulation: in the WinAC RTX Config tool, click Stop. Watch the file modification timestamp update within a few seconds. Restart and confirm tags restored.
  4. UPS test: with the SITOP DC UPS or third-party UPS at full charge, pull the 24 V mains input. Confirm the SITOP UPS Manager log shows the battery low event fired the configured action. Confirm the IPC shut down within the buffer window. Restore mains, boot, and confirm tags restored.
  5. Endurance test: cycle power 5 to 10 times under varying load. Inspect the SITOP UPS log for false triggers and confirm retain integrity every cycle.

Troubleshooting Matrix

Symptom Likely cause Remediation
Retain lost on power cycle, retained on Windows restart No PowerLoss signal to WinLC Install SITOP DC UPS or IPC with PowerLoss support
Retain lost even on Windows restart Retain not configured in STEP 7, or persistence folder read-only Re-check Retain attribute and write ACL on persistence folder
IPC does not shut down on battery low UPS Manager action not configured to run a program Set action to Run program with full path to WinLC_Shutdown.exe
WinLC service does not stop when script runs Script runs as logged-in user, no permission Move script to Computer Configuration in gpedit.msc, or set highest privileges on Task Scheduler task
Retain file on disk is corrupt after recovery Power lost mid-write; buffer too short Increase UPS hold-up time and / or replace battery (lead-acid loses capacity with age)
WinLC stops but PC keeps running indefinitely shutdown command missing or failing Confirm shutdown.exe is present and not blocked by policy
PowerLoss signal fires too often on minor sags UPS threshold too aggressive Increase battery low threshold in SITOP UPS Manager
After firmware update on SITOP UPS1600, retain lost PROFINET device name or IP changed Re-assign PROFINET station name in SITOP UPS Manager
Retain lost only on cold start, fine on warm Retain file path not on persistent disk or shadowed by overlay Move WinAC RTX data path to a non-overlaid volume

Platform and OS Considerations

OS / Platform Notes
Windows XP Original Siemens FAQ 31410254 context. GPEDIT.msc shutdown scripts work natively.
Windows 7 x32 / x64 Officially supported by WinAC RTX 2010. Group Policy shutdown scripts run with system privileges. The original poster's environment.
Windows 10 Supported by WinAC RTX 2010 SPx. Same Group Policy path. Fast Startup must be considered - it can mask the shutdown script if the system goes to hibernation instead of a true shutdown.
Windows 11 / Server 2019+ Verify WinAC RTX version compatibility with the OS; WinAC RTX 2010 SP2 or later is typically required. SITOP UPS1600 with PROFINET is the recommended UPS for new builds.
Domain-joined machine Use Group Policy Management Console (GPMC) at the OU level instead of local gpedit.msc; the local edit will be overwritten by domain policy refresh.
Dell / Advantech / Kontron IPC No native PowerLoss signal. SITOP DC UPS module is mandatory.
Siemens SIMATIC IPC Native PowerLoss signal in supported SKUs. SITOP UPS module still recommended for the battery buffer.
Note: The original poster reported the environment as Windows 7 x32 PRO on a Dell PC. The recommended path for that specific combination is a SITOP DC UPS module (USB or PROFINET) with SITOP UPS Manager invoking WinLC_Shutdown.exe on battery low. The Group Policy shutdown script path remains useful as a layered trigger.

Frequently Asked Questions

Why are my STAT variables not retained after a power loss in WinAC RTX even though the Retain checkbox is set?

WinAC RTX stores retain data in host RAM and only persists it to disk when the WinLC runtime receives a stop event. A bare power loss gives the runtime no time to save. Install a SITOP DC UPS module with SITOP UPS Manager invoking WinLC_Shutdown.exe, or use a Siemens SIMATIC IPC that exposes a PowerLoss signal, so the runtime gets a controlled stop window of at least 20 seconds.

Which SITOP DC UPS module should I use with WinAC RTX?

The SITOP DC UPS modules 6EP1931-2DC and 6EP1931-2EC paired with SITOP UPS500 lead-acid or LiFePO4 buffer modules are the classic configuration. For new builds, the SITOP UPS1600 with PROFINET is recommended because it integrates cleanly with STEP 7 and exposes battery state over PROFINET to the PLC.

Can I trigger WinLC_Shutdown.exe from a third-party UPS on Windows 7 x32?

Yes. Configure the UPS vendor's monitoring software to call a batch file on low battery, and register the same batch file as a shutdown script through gpedit.msc at Computer Configuration > Windows Settings > Scripts (Startup/Shutdown) > Shutdown. Use a Windows Task Scheduler task bound to the UPS low-battery event ID as a secondary trigger for redundancy.

What is the minimum buffer time required to safely retain data in WinAC RTX?

Plan for 20 seconds at the IPC's worst-case load. This covers the OB1 cycle finish, the retain-data flush to disk, the WinLC service stop, and the Windows shutdown sequence. Lead-acid SITOP modules lose 30 to 50 percent capacity at low temperatures, so derate accordingly for cold cabinets.

Do I need to do anything special in STEP 7 to mark a DB as retain in WinAC RTX?

Open the DB properties in SIMATIC Manager and enable the Retain attribute, or check the Retain column in the symbol table for each STAT variable. Recompile and download the program. Verify the retain persistence file is written on the next controlled stop. The STEP 7 setting alone is not sufficient to survive uncontrolled power loss - the runtime still needs a PowerLoss trigger.

Back to blog