Overview: WinAC RTX Retain Variable Persistence
Siemens WinAC RTX (Windows Automation Center Real-Time eXtension) is a software PLC that executes STEP 7 programs on a Windows-based industrial PC rather than on a dedicated hardware CPU such as the SIMATIC S7-300 or S7-400. Unlike a hardware PLC, which retains remanent data through internal battery-backed SRAM, non-volatile FRAM, or MMC (Micro Memory Card) persistence, WinAC RTX stores its retain area in the host PC's working memory. Power loss therefore requires a coordinated shutdown sequence to flush that memory to a persistence file on disk before the Windows host is de-energized.
The RETAIN attribute on a STAT variable in STEP 7 / SIMATIC Manager only marks the tag as eligible for the retention mechanism; it does not by itself guarantee survival of an uncontrolled power loss. Engineers familiar with the S7-300 expect the Retain checkbox to provide identical behavior to a hardware CPU where remanent data is preserved across a power cycle. On WinAC RTX, that expectation is incorrect without additional infrastructure.
A successful retain implementation on WinAC RTX requires three coordinated components:
- A non-volatile media (HDD, SSD, or industrial CFast) for the persistence file.
- An early warning of impending power failure delivered to the WinLC runtime.
- A controlled shutdown path that allows the WinLC runtime to serialize its retain area to disk before the operating system loses power.
This article covers the root cause of the typical "retain lost on power cycle, but preserved on Windows restart" symptom, and provides four field-proven solutions with commissioning and verification steps.
Retain Behavior Comparison: S7-300 vs WinAC RTX
The diagnostic value of the symptom "retain lost on power cycle, but preserved on a Windows restart" becomes clear when the two retention models are compared side by side.
| Property | SIMATIC S7-300 / S7-400 | WinAC RTX (WinLC) |
|---|---|---|
| Retain storage media | Battery-backed SRAM, FRAM, or MMC | Host PC RAM, written to disk on shutdown |
| Time to persist data | Always powered (battery) | Milliseconds to seconds during shutdown |
| Power loss detection | Hardware buffer / supercap | Requires PowerLoss signal or UPS event |
| Action on power loss | CPU continues from buffered energy or restarts with retained data intact | Runtime must be told to stop, persist, and exit before Windows halts |
| RETAIN bit in STEP 7 | Marks tag as remanent; backed by hardware | Marks tag as retain; only persisted if WinLC is given a graceful shutdown window |
The fact that data survives a Windows restart (user-initiated Start > Restart) confirms the retain mechanism itself is correctly configured: the WinLC runtime executes its SaveRetainData() path during normal stop, and the values land on disk. The failure on power cycle confirms that the runtime never had the chance to run that save path because the host lost power without a prior shutdown trigger.
Problem Description
Observed symptoms in a typical WinAC RTX deployment:
- All STAT variables marked with the Retain attribute in the STEP 7 symbol table or DB editor reset to their default initial values after an uncontrolled mains power loss.
- The same variables retain their values across a Windows restart triggered from the Start menu or by an
shutdown /rcommand. - WinCC, WinCC flexible, or third-party HMI running on the same PC sees the tags revert to defaults, producing recipe loss, counter resets, and state-machine corruption on the next OB1 scan.
- The WinLC service is configured for Autostart on boot; OB100 (warm restart) and OB101 (hot restart) do not find valid retain data to restore.
This is the canonical signature of missing PowerLoss notification to the WinAC RTX runtime, not a bug in STEP 7 retain configuration.
Root Cause: The PowerLoss Signal
WinAC RTX distinguishes between three shutdown classes, and the difference matters:
| Shutdown class | Trigger | Retain data saved? |
|---|---|---|
| Controlled stop (e.g. WinLC stop from SIMATIC Manager) | Operator or HMI command | Yes - WinLC flushes retain to disk |
| Windows shutdown / restart | OS-initiated stop | Yes - OS triggers WinLC stop via service control |
| Uncontrolled power loss | Mains removed, battery exhausted | No - runtime never receives a stop event |
To convert an uncontrolled power loss into a controlled stop, the WinAC RTX runtime must receive a PowerLoss signal in time to:
- Finish the current OB1 cycle.
- Execute OB80 / OB121 / OB122 error handling if needed.
- Run internal retain-save routine to disk (typically
%ProgramData%\Siemens\Automation\WinAC\Retain\*.dator installation-specific path). - Signal the Windows service control manager to stop the PC.
The buffer time required is typically 5 to 30 seconds depending on program size, number of retain tags, and disk write speed. This buffer is delivered by either:
- A Siemens SIMATIC IPC whose BIOS and power supply expose a PowerFail signal (often via the SIMATIC motherboard monitoring ASIC to WinAC RTX over a Siemens-proprietary interface or a configured GPIO).
- An external UPS (SITOP DC UPS recommended) whose monitoring software triggers
WinLC_Shutdown.exewhen battery capacity drops below a threshold.
System Architecture: Properly Buffered WinAC RTX
Diagnostic Procedure
Before changing configuration, run the following checks in order. Each one isolates one variable in the failure chain.
- Confirm the host PC is not a Siemens IPC with a documented PowerLoss output. Open Device Manager, expand System devices, and look for a SIMATIC or Siemens watchdog / power management device. If present, the BIOS / WinAC configuration tool should expose the PowerLoss pin; consult the IPC manual for the specific SKU. If not present, the IPC is not signalling WinAC, and a UPS solution is mandatory.
- Verify the retain configuration in STEP 7. In SIMATIC Manager, open the S7 program, right-click the DB or the symbol containing the STAT, and confirm the Retain column shows a check mark in the symbol table for the affected tags. For an S7-compatible WinAC project the retain mask is also visible under Properties > Retain.
-
Inspect the persistence path on disk. After a clean Windows restart (where retain does survive), navigate to the WinAC retain data folder (default
C:\ProgramData\Siemens\Automation\WinACor the path selected during WinAC RTX setup). Confirm files with extensions.rdb,.dat, or*.binaare written and have recent modification times. If they are present, the save path itself is healthy. -
Test the UPS path. With a SITOP DC UPS (or equivalent) installed, pull the mains plug. Watch the SITOP UPS Manager (or the equivalent monitoring tool) and confirm
WinLC_Shutdown.exeis invoked within the configured threshold. The IPC should then perform an orderly Windows shutdown, and the retain values should be present on the next power-up. - Inspect the Event Log. After a failure, look under Windows Logs > Application for entries from WinLC, S7wnresx, or the SITOP UPS service. Error code 0x80070005 (access denied), 0x80004005 (unspecified), or simply a missing WinLC stop event before OS halt confirms the runtime never received a shutdown instruction.
Solution A: Siemens IPC with PowerLoss Signaling
On supported SIMATIC IPCs (e.g. SIMATIC IPC227G, IPC277G, IPC427G, IPC647E, IPC847E) the on-board power supply and BIOS expose a PowerFail signal that WinAC RTX can subscribe to. In this configuration, the IPC itself is the buffer: its internal hold-up time plus any installed UPS module is sized so that WinAC RTX receives a controlled stop notification through the IPC interface, persists its retain data, and then triggers Windows shutdown.
Commissioning steps:
- In BIOS, enable the Power Failure or PowerGood interrupt if it is exposed and confirm WinAC RTX is the consumer (not a third-party management agent).
- Install the SIMATIC IPC driver and management components shipped with the IPC; on modern IPCs this is the SIMATIC IPC DiagBase / SIMATIC IPC Configuration Center package.
- In the WinAC RTX configuration tool (Start > Siemens Automation > WinAC RTX > WinAC Config), set the PowerLoss source to SIMATIC IPC or the equivalent local enumerator.
- Set the hold-up time in the IPC BIOS to a value that gives the WinLC service a minimum of 10 s to flush retain data; 20 s is a safe default for typical programs of up to a few hundred retain tags.
Solution B: SITOP DC UPS with WinLC_Shutdown.exe
For non-Siemens IPCs (Dell, Advantech, Beckhoff, Kontron, etc.) the recommended Siemens-supported path is a SITOP DC UPS module buffering the 24 V rail, paired with the SITOP UPS Manager software that calls WinLC_Shutdown.exe on low-battery threshold. This is the architecture described in Siemens Support Entry 31410254 - Preventing loss of retained data with SITOP DC UPS and WinAC RTX.
Hardware components
| Component | Role | Example SKU |
|---|---|---|
| 24 V DC industrial PSU | Mains conversion | SITOP PSU8200 / PSU100 |
| SITOP DC UPS module | Bridging module with battery | 6EP1931-2DC, 6EP1931-2EC, SITOP UPS1600 |
| Energy storage | Lead-acid or LiFePO4 buffer | SITOP UPS500 series battery modules |
| IPC host | Runs WinAC RTX + UPS Manager | Any x86 IPC with USB or PROFINET |
Software components
- SITOP UPS Manager (part of the SITOP DC UPS toolset) - monitors the UPS state, exposes battery state, and triggers actions on thresholds.
-
WinLC_Shutdown.exe - WinAC RTX utility that performs an orderly WinLC stop and a Windows shutdown. Typical path:
C:\Program Files\Siemens\Automation\WinAC RTX\WinLC_Shutdown.exe. Run with elevated privileges.
Commissioning steps
- Install the SITOP DC UPS module between the 24 V supply and the IPC's 24 V input. Verify polarity and the recommended wire cross-section from the UPS manual.
- Connect the SITOP UPS module to the IPC via USB (classic SITOP DC UPS) or PROFINET (SITOP UPS1600). The PROFINET variant is preferred on PROFINET-native WinAC RTX installations because the integration is documented in TIA Portal / STEP 7.
- Install the SITOP UPS Manager. Configure the COM port or PROFINET device matching the hardware.
- Set the battery low threshold to a value that gives at least 20 s of hold-up at the IPC's worst-case load. Lead-acid SITOP modules typically derate 30 to 50% at cold temperatures - derate the threshold accordingly.
- In SITOP UPS Manager, configure the action on battery low: run
WinLC_Shutdown.exe /shutdown(or the documented flag set in the help). The action must be set to Run program, not just Log. - Perform a controlled mains-loss test: with the program in RUN, pull the 24 V input to the SITOP DC UPS module. Verify in the SITOP UPS Manager log that the script fired, that WinLC transitioned to STOP, and that the IPC shut down within the configured window.
- Restore mains, restart the IPC, and verify that the retain values match the pre-power-loss state.
WinLC_Shutdown.exe differ between WinAC RTX 2008, 2010, and 2010 SPx. Read the help (WinLC_Shutdown.exe /? or the help bundled with the WinAC RTX installation) for the version installed on the host before scripting around it.Solution C: Third-Party UPS with Windows Shutdown Script
When a non-Siemens UPS is already installed (APC, Eaton, Vertiv, CyberPower, generic USB HID UPS), the same idea applies: when the UPS signals "on battery low", Windows must run a script that stops WinLC and shuts down the host. The Windows mechanism for "scripts that run at shutdown" is a Group Policy shutdown script, configured through gpedit.msc on Windows Pro / Enterprise, or Group Policy Management on domain-joined machines.
The shutdown script must do three things, in order:
- Stop the WinLC service gracefully, which is what triggers the retain-data save path. The command is typically
net stop "S7WinLC"(the exact service name depends on the WinAC RTX version - check services.msc). On WinAC RTX 2010 and later the service name is usually WinLC or S7WinLC. - Wait for the service to reach the STOPPED state with a timeout. A 30 s timeout is typical.
- Initiate Windows shutdown with
shutdown /s /t 0 /for callWinLC_Shutdown.exeif present, which performs both steps internally.
A robust batch file C:\Scripts\winac_shutdown.bat typically looks like:
@echo off
rem Stop WinLC to flush retain data
net stop "S7WinLC" /y
timeout /t 5 /nobreak >nul
rem Verify stop; force-kill if still running after 30s
sc query "S7WinLC" | find "STOPPED" >nul
if errorlevel 1 (
timeout /t 30 /nobreak >nul
taskkill /f /im WinLC.exe
)
rem Shutdown Windows
shutdown /s /t 0 /f /c "UPS battery low - WinAC controlled shutdown"
For higher reliability on systems where the UPS-to-host signal may be missed, layer two triggers:
- The UPS vendor's power-chute / IPP / Network Card software, which monitors battery state and calls the same batch file on battery low.
- A Windows Task Scheduler task bound to Event ID 1 in the System log from source UPS, as a fallback path.
Configuring a Group Policy Shutdown Script
- Open
gpedit.msc(Group Policy Editor). On Windows Pro / Enterprise this is bundled; on Windows Home it is not present and the registry keyHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ShutdownWithoutLogonand the Scripts registry path must be used as fallback. - Navigate to Computer Configuration > Windows Settings > Scripts (Startup / Shutdown).
- Double-click Shutdown in the right pane.
- Click Add, then Browse to the batch file created in Solution C. Windows does not pass parameters to shutdown scripts in this path; the script must be self-contained.
- Click OK and force a policy refresh with
gpupdate /forcefrom an elevated command prompt. - Verify by running
gpresult /rand confirming the script is listed under Applied Group Policy Objects > Scripts.
Solution D: Windows Task Scheduler with UPS Event
When the UPS vendor does not provide a clean "battery low" hook, a Windows Task Scheduler task can monitor the event log and fire the same shutdown script. Steps:
- Open
taskschd.msc. - Create Task (not Basic Task) with Run whether user is logged on or not and Run with highest privileges.
- Trigger: On an event > Custom > New Event Filter > By source: UPS, Event ID: 1 (or the ID documented by your UPS vendor for low battery).
- Action: Start a program >
C:\Scripts\winac_shutdown.bat. - Conditions: leave Start the task only if the computer is on AC power unchecked - we explicitly want the task to fire when AC is gone.
This layered trigger is the practical answer to the original question "how do I start WinLC_Shutdown.exe when the UPS battery is low?"
SITOP UPS Manager Configuration Reference
| Parameter | Typical value | Notes |
|---|---|---|
| COM port / PROFINET device | COM1, COM3, or detected PROFINET station | Match to physical connection |
| Battery low threshold | 20-30% of nominal capacity | Must allow 20 s hold-up at worst-case load |
| Action on battery low | Run program: WinLC_Shutdown.exe | Test with a no-load test first |
| Action on mains return | None, or power on IPC if BIOS supports | Set per plant policy |
| Log verbosity | Debug during commissioning, Info in production | Debug writes to disk |
| Heartbeat to PC | 5 s | Shorter = faster detection, more load on host |
Power Loss Timing Sequence
Verification Procedure
Run these checks after any retain-related configuration change. Each is binary - it passes or it fails the retain pipeline.
- Static check: open SIMATIC Manager, recompile the S7 program, and confirm no warnings about unretained tags where retain is expected.
- Disk check: confirm the retain persistence files exist and have a recent modification timestamp after a clean Windows restart.
- Controlled-shutdown simulation: in the WinAC RTX Config tool, click Stop. Watch the file modification timestamp update within a few seconds. Restart and confirm tags restored.
- UPS test: with the SITOP DC UPS or third-party UPS at full charge, pull the 24 V mains input. Confirm the SITOP UPS Manager log shows the battery low event fired the configured action. Confirm the IPC shut down within the buffer window. Restore mains, boot, and confirm tags restored.
- Endurance test: cycle power 5 to 10 times under varying load. Inspect the SITOP UPS log for false triggers and confirm retain integrity every cycle.
Troubleshooting Matrix
| Symptom | Likely cause | Remediation |
|---|---|---|
| Retain lost on power cycle, retained on Windows restart | No PowerLoss signal to WinLC | Install SITOP DC UPS or IPC with PowerLoss support |
| Retain lost even on Windows restart | Retain not configured in STEP 7, or persistence folder read-only | Re-check Retain attribute and write ACL on persistence folder |
| IPC does not shut down on battery low | UPS Manager action not configured to run a program | Set action to Run program with full path to WinLC_Shutdown.exe |
| WinLC service does not stop when script runs | Script runs as logged-in user, no permission | Move script to Computer Configuration in gpedit.msc, or set highest privileges on Task Scheduler task |
| Retain file on disk is corrupt after recovery | Power lost mid-write; buffer too short | Increase UPS hold-up time and / or replace battery (lead-acid loses capacity with age) |
| WinLC stops but PC keeps running indefinitely | shutdown command missing or failing | Confirm shutdown.exe is present and not blocked by policy |
| PowerLoss signal fires too often on minor sags | UPS threshold too aggressive | Increase battery low threshold in SITOP UPS Manager |
| After firmware update on SITOP UPS1600, retain lost | PROFINET device name or IP changed | Re-assign PROFINET station name in SITOP UPS Manager |
| Retain lost only on cold start, fine on warm | Retain file path not on persistent disk or shadowed by overlay | Move WinAC RTX data path to a non-overlaid volume |
Platform and OS Considerations
| OS / Platform | Notes |
|---|---|
| Windows XP | Original Siemens FAQ 31410254 context. GPEDIT.msc shutdown scripts work natively. |
| Windows 7 x32 / x64 | Officially supported by WinAC RTX 2010. Group Policy shutdown scripts run with system privileges. The original poster's environment. |
| Windows 10 | Supported by WinAC RTX 2010 SPx. Same Group Policy path. Fast Startup must be considered - it can mask the shutdown script if the system goes to hibernation instead of a true shutdown. |
| Windows 11 / Server 2019+ | Verify WinAC RTX version compatibility with the OS; WinAC RTX 2010 SP2 or later is typically required. SITOP UPS1600 with PROFINET is the recommended UPS for new builds. |
| Domain-joined machine | Use Group Policy Management Console (GPMC) at the OU level instead of local gpedit.msc; the local edit will be overwritten by domain policy refresh. |
| Dell / Advantech / Kontron IPC | No native PowerLoss signal. SITOP DC UPS module is mandatory. |
| Siemens SIMATIC IPC | Native PowerLoss signal in supported SKUs. SITOP UPS module still recommended for the battery buffer. |
WinLC_Shutdown.exe on battery low. The Group Policy shutdown script path remains useful as a layered trigger.Frequently Asked Questions
Why are my STAT variables not retained after a power loss in WinAC RTX even though the Retain checkbox is set?
WinAC RTX stores retain data in host RAM and only persists it to disk when the WinLC runtime receives a stop event. A bare power loss gives the runtime no time to save. Install a SITOP DC UPS module with SITOP UPS Manager invoking WinLC_Shutdown.exe, or use a Siemens SIMATIC IPC that exposes a PowerLoss signal, so the runtime gets a controlled stop window of at least 20 seconds.
Which SITOP DC UPS module should I use with WinAC RTX?
The SITOP DC UPS modules 6EP1931-2DC and 6EP1931-2EC paired with SITOP UPS500 lead-acid or LiFePO4 buffer modules are the classic configuration. For new builds, the SITOP UPS1600 with PROFINET is recommended because it integrates cleanly with STEP 7 and exposes battery state over PROFINET to the PLC.
Can I trigger WinLC_Shutdown.exe from a third-party UPS on Windows 7 x32?
Yes. Configure the UPS vendor's monitoring software to call a batch file on low battery, and register the same batch file as a shutdown script through gpedit.msc at Computer Configuration > Windows Settings > Scripts (Startup/Shutdown) > Shutdown. Use a Windows Task Scheduler task bound to the UPS low-battery event ID as a secondary trigger for redundancy.
What is the minimum buffer time required to safely retain data in WinAC RTX?
Plan for 20 seconds at the IPC's worst-case load. This covers the OB1 cycle finish, the retain-data flush to disk, the WinLC service stop, and the Windows shutdown sequence. Lead-acid SITOP modules lose 30 to 50 percent capacity at low temperatures, so derate accordingly for cold cabinets.
Do I need to do anything special in STEP 7 to mark a DB as retain in WinAC RTX?
Open the DB properties in SIMATIC Manager and enable the Retain attribute, or check the Retain column in the symbol table for each STAT variable. Recompile and download the program. Verify the retain persistence file is written on the next controlled stop. The STEP 7 setting alone is not sufficient to survive uncontrolled power loss - the runtime still needs a PowerLoss trigger.