WinCC Audit Client Login Logout Not Captured: Troubleshooting

David Krause13 min read
SiemensTroubleshootingWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

In a WinCC V7.x server-client architecture with the WinCC Audit option package installed, operator actions performed on a client station are partially captured by the Audit Trail database. Field changes made through I/O fields on the client runtime are recorded correctly, but user login and logout events originating from the WinCC client are missing from the Audit Trail. The same WinCC server captures login and logout events from its local WinCC Runtime user correctly, which isolates the fault to the client-side operator message forwarding path rather than to the SIMATIC Logon configuration or the Audit database itself.

This behavior is a recurring configuration defect when WinCC Audit is first deployed in a multi-user project. The Audit Editor in WinCC exports operator messages from the Alarm Logging subsystem, not directly from the runtime user administration. When the Alarm Logging standard server for a client PC is not assigned, the operator messages that represent login and logout actions never reach the Alarm Logging archive, and therefore never reach the Audit Trail database. I/O field changes are captured through a different code path (variable logging), which is why they continue to appear even when the Alarm Logging standard server is missing.

Affected versions: WinCC V7.2 through V7.5 SP2 with the WinCC Audit option (article number 6AV6371-1CA07-2AX0 in V7.2). The mechanism described also applies to WinCC/Audit V8.0 and V8.1 on TIA Portal-era runtime licensing, although the editor path differs.

Root Cause Analysis

The Audit Trail database in WinCC is populated from two distinct sources:

  1. Variable logging audit actions – triggered when an operator writes through a configured I/O field, button, or slider that is bound to a logged tag. These actions are forwarded by the WinCC Runtime directly to the Audit component installed on the server hosting the project.
  2. Operator messages from Alarm Logging – login, logout, user change, and authorization-change events are generated as WinCC system messages (message numbers 1001000 through 1001099 in the default message configuration). The Audit Editor subscribes to the Alarm Logging archive and exports these messages to the Audit Trail database.

For the second path to function on a client PC, the client must be configured to forward its Alarm Logging messages to a specific WinCC server. This is done by assigning a Standard Server for the Alarm Logging component on each client. Without this assignment, Alarm Logging messages generated on the client are dropped at the client runtime because no destination server is known.

The configuration location for this assignment is the WinCC Explorer on the client, not the server. In the WinCC Explorer project tree, expand Server Data, right-click to open the context menu, and select Standard Server.... The dialog lists all imported symbolic computer names of WinCC servers. Selecting the appropriate server for the Alarm Logging component (also referred to as "Component Alarms") establishes the forwarding path.

Architecture Prerequisites

Before adjusting the standard server assignment, verify that the following prerequisites are met on every workstation that participates in the audit chain:

Requirement Detail
WinCC Audit license Valid license key on the WinCC server (single-station or server license). Client PCs require a WinCC RT license; the Audit option itself runs only on the server.
SIMATIC Logon Installed and configured on every server and client. Central user administration must point to the same Windows domain or SIMATIC Logon server.
Symbolic computer names Each WinCC server must have a unique symbolic computer name configured in WinCC Explorer > Computer Properties. The name must be reachable from each client over TCP port 80 (HTTP) and the configured SQL port (default 1433).
Alarm Logging configuration The Alarm Logging archive must be active on the target server. Confirm via WinCC Explorer > Alarm Logging > Archives that the short-term and long-term archives are configured.
User messages enabled Message numbers 1001000 (User logged in), 1001001 (User logged out), and related system messages must not be suppressed in the message configuration.

Step-by-Step Configuration: Assigning the Alarm Logging Standard Server

The standard server assignment is performed on the client PC using the WinCC Explorer.

  1. Open WinCC Explorer on the client PC using the WinCC project that was replicated from the server (or via the WinCC client configuration tool).
  2. In the project tree on the left, locate and expand Server Data.
  3. Right-click the Server Data node. From the context menu, select Standard Server...
  4. The Standard Server dialog opens. The Symbolic computer name column lists every WinCC server whose project data has been imported into this client configuration. Servers are listed only if their packages have been successfully loaded.
  5. In the row labeled Alarm Logging (Component Alarms), select the radio button next to the symbolic name of the WinCC server that hosts the Alarm Logging archive.
  6. Click OK to save. WinCC writes the assignment to the client's package configuration.
  7. Restart the WinCC Runtime on the client for the change to take effect. A hot reload is not supported for standard server changes in V7.x.
Critical: The Alarm Logging standard server must be assigned on every client that should forward operator messages. A project-wide setting is not propagated automatically from the server.

Step-by-Step Configuration: Creating the Audit Trail Database

If the Audit Trail database has not been created, or if it points to a non-existent SQL instance, login/logout events will not be persisted even when the Alarm Logging archive receives them. Follow the procedure documented in Siemens KB entry 109775427.

  1. On the WinCC server, open the WinCC Explorer and select Audit Editor in the navigation tree.
  2. If the Audit Trail database has not been created, right-click Audit and select Create Audit Trail Database... Provide the SQL Server instance, database name, and authentication mode.
  3. Right-click Audit and select Audit Settings... to open the configuration dialog.
  4. In the Audit Trail Server field, select the symbolic computer name of the WinCC server that should host the Audit Trail. Only one server per project may hold the Audit Trail role.
  5. Confirm the retention and archive settings, then save. The Audit service restarts automatically.
  6. Activate the project on the server before activating runtime on clients.

Refer to the Siemens Industry Online Support entry How do you set up WinCC Audit? How do you select the Audit Trail server and create a database? for the complete dialog sequence with screen references.

Verification Procedures

After applying the configuration changes, validate the chain end-to-end:

Verification 1: Alarm Logging Archive Contains Login/Logout Messages

  1. On the WinCC server, open the WinCC Alarm Control (online) within WinCC Explorer or the Graphics Runtime.
  2. Filter for message numbers 1001000 and 1001001 (or the customized equivalents if the message configuration was modified).
  3. Trigger a login/logout cycle on the client and confirm that the corresponding messages appear in the server-side alarm view.

Verification 2: Audit Trail Database Contains the Events

  1. Open the Audit Viewer on the WinCC server: WinCC Explorer > Audit > Audit Viewer.
  2. Apply a time filter covering the test login cycle.
  3. Confirm that entries with action type UserLogin and UserLogout appear with the client workstation's computer name in the Workstation column.

Verification 3: Database Direct Query (Optional)

For deep validation, query the SQL database directly. The Audit Trail schema in WinCC V7.x is named CC_AuditTrail by default. A typical login record query:

SELECT [TIMESTAMP], [USERNAME], [WORKSTATION], [ACTION], [RESULT]
FROM CC_AuditTrail
WHERE ACTION IN ('UserLogin', 'UserLogout')
ORDER BY TIMESTAMP DESC;

Empty result sets indicate that the Audit service has not yet ingested messages; check the Windows Event Log under Applications and Services Log > Siemens Automation > WinCC Audit for ingestion errors.

WinCC/Audit V8.1 Considerations

WinCC/Audit V8.1 (TIA Portal V18/V19 era) changes the configuration surface but retains the same forwarding logic. The Audit Trail database role, the Alarm Logging standard server assignment, and the SIMATIC Logon integration remain the three pillars. Notable V8.1 specifics:

  • The Audit Trail database is created via TIA Portal > Runtime settings > Audit, and the underlying SQL Server must be installed locally or referenced via a connection string.
  • Backup and restore of the Audit Trail database can be performed with the WinCC native tool described in Siemens KB entry WinCC/Audit V8.1 - Backup and restore database. The same entry documents import of audit trail data from TXT, CSV, and RDB file formats.
  • The standard server assignment is performed in the WinCC Explorer on the client, identical to V7.x. The dialog text changed slightly: in V8.1 the menu item reads Standard Server for Alarm Logging.

WinCC Unified Audit (TIA Portal V20)

WinCC Unified replaces the WinCC Explorer configuration model with the TIA Portal project view and introduces the Audit Viewer (RT Unified) object for runtime visualization. Although the underlying forwarding principle is similar, the configuration moves into the HMI device configuration:

  1. In TIA Portal, open the HMI device (Unified PC or Unified Comfort Panel) and navigate to Runtime settings > Audit.
  2. Enable the Audit option and select the Audit Trail server.
  3. Configure the user administration to use SIMATIC Logon.
  4. Insert the Audit Viewer object from the toolbox into a screen. Refer to the documentation page Audit Viewer (RT Unified) - WinCC Unified for parameter details.

In a Unified distributed system, the Audit Trail server role is assigned to a single Unified PC station; clients connect to that station for read access via the Audit Viewer object.

Troubleshooting Matrix

Symptom Likely Cause Corrective Action
Client I/O field changes captured, login/logout missing Alarm Logging standard server not assigned on the client Configure Standard Server > Alarm Logging on the client
Both server and client login/logout missing Audit Trail database not created or Audit service stopped Create Audit Trail database; restart the "Siemens WinCC Audit" service
Login/logout visible in Alarm Logging archive but not in Audit Viewer Audit Editor not subscribing to Alarm Logging archive Open Audit Editor > Audit Settings > confirm "Operator messages from Alarm Logging" is enabled
Messages missing from Alarm Logging archive on the server SIMATIC Logon not properly linked on the client Re-link SIMATIC Logon to the WinCC project on the client; verify GSSAPI user mapping
Audit Viewer shows old entries only Audit retention period expired or archive path offline Verify archive storage path is reachable; extend retention in Audit Settings
SQL error on Audit Trail database creation SQL Server service not running or insufficient privileges Start MSSQLSERVER service; grant dbcreator role to the WinCC runtime user
Time stamps on client events offset from server Time synchronization drift between stations Configure NTP on all servers and clients; max drift < 5 seconds

Common Configuration Pitfalls

Beyond the standard server omission, several related defects produce similar symptoms:

  • Package not refreshed after server change. If the WinCC server's symbolic name was renamed, the client's .pn package must be re-imported before the new server appears in the Standard Server list.
  • Multiple servers, wrong selection. In a redundant server pair, the standard server should point to the master server (or to a virtual name if fronted by a redundancy gateway). Pointing to the standby server results in lost messages during failover.
  • User messages suppressed. The Alarm Logging message configuration can disable system messages. Check WinCC Explorer > Alarm Logging > Message Configuration and confirm message class System is active.
  • Antivirus quarantine of WinCC Audit DLLs. Real-time AV scanning of the WinCC installation directory can block the Audit service from writing to the SQL database. Add an exclusion for the WinCC project directory and the SQL data path.
  • Firewall blocking TCP 1433. In distributed installations the SQL port must be open between the WinCC server and any remote SQL hosting the Audit Trail database.

Operational Best Practices

  1. Document the standard server assignment per client in the project functional specification. This accelerates troubleshooting during commissioning and after hardware swaps.
  2. Schedule a daily export of the Audit Trail database to an offline location. WinCC/Audit V8.1 supports automated export to TXT, CSV, and RDB formats as documented in KB 109977112.
  3. Retain Alarm Logging archives for at least 30 days even if the Audit Trail database is the primary record. The archive acts as the upstream source if Audit ingestion is interrupted.
  4. Use the same Windows time source across all servers and clients. Time skew between workstations produces out-of-order audit entries that complicate forensic review.
  5. Enable the Windows Event Log channel for the Audit service in production. Ingestion failures surface there with specific event IDs.

Migration Notes: V7.x to V8.x

When migrating a WinCC V7.x project with WinCC Audit to a TIA Portal V18/V19/V20 runtime, the Audit Trail database does not migrate automatically. The recommended sequence is:

  1. Export the Audit Trail data to RDB format using the V7.x Audit Editor's export function.
  2. Recreate the Audit Trail database structure on the target SQL Server.
  3. Import the RDB data into the new database using the V8.x import tool.
  4. Reassign the Alarm Logging standard server on each client (the project tree node moved from "Server Data" to "Runtime settings > Connections").
  5. Verify login/logout capture end-to-end before decommissioning the V7.x server.

Summary

Client-side login and logout events are not captured by the WinCC Audit Trail when the client runtime has no Alarm Logging standard server assigned. The Audit Editor draws operator messages from the Alarm Logging archive, and without that forwarding target the messages are dropped at the client. Assigning the Alarm Logging standard server on each client through WinCC Explorer > Server Data > Standard Server restores the chain. The same configuration principle applies to WinCC/Audit V8.1 and to WinCC Unified Audit in TIA Portal V20, with the configuration dialog relocated to the respective runtime settings. Always validate by inspecting the Alarm Logging archive on the server before reviewing the Audit Trail database; an empty archive will always produce an empty Audit Trail regardless of downstream configuration.

Why are client user login and logout events missing from the WinCC Audit Trail database?

The Alarm Logging standard server is not assigned on the client PC. WinCC Audit pulls operator messages from the Alarm Logging archive; without a standard server, login/logout messages generated on the client never reach the archive. Open WinCC Explorer on the client, right-click Server Data, select Standard Server, and assign the Alarm Logging component to the desired WinCC server.

How do I create the WinCC Audit Trail database and select the Audit Trail server?

In WinCC Explorer on the server, open the Audit Editor, right-click Audit, and choose Create Audit Trail Database. Specify the SQL Server instance and authentication. Then in Audit Settings, select the symbolic computer name of the server that should host the Audit Trail. Refer to Siemens KB 109775427 for the dialog sequence.

I/O field changes are captured but login/logout is not. What does this indicate?

Variable-driven audit actions (such as I/O field writes) are forwarded through a different path than operator messages from Alarm Logging. When I/O field changes appear but login/logout does not, the Alarm Logging forwarding chain is the likely defect. Verify the standard server assignment and confirm that Alarm Logging message numbers 1001000 and 1001001 are not suppressed.

Does the Alarm Logging standard server need to be configured on every client?

Yes. The standard server assignment is per-client and is not propagated from the server or from other clients. Each WinCC client that should forward operator messages to the Audit Trail must have the Alarm Logging standard server set explicitly. After changing the assignment, restart the WinCC Runtime on the client for the new setting to take effect.

How do I back up and restore a WinCC/Audit V8.1 database and import historical data?

Use the WinCC native backup and restore tool documented in Siemens KB 109977112. Historical audit trails can be imported from TXT, CSV, or RDB file formats using the same entry's import procedure. After restoration, restart the Siemens WinCC Audit service and verify connectivity from the Audit Viewer on a client.

Back to blog