WinCC Flexible Tag Editor: Mass Tag Creation and Find/Replace

David Krause15 min read
Best PracticesHMI ProgrammingSiemens
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview of WinCC Flexible Tag Management

WinCC Flexible ES is the Siemens HMI engineering suite released in 2005 and maintained through WinCC Flexible 2008 SP5. It configures the SIMATIC HMI panel family — OP 73 micro panels, OP 77A/B, TP 170A/B, TP 177A/B, TP 277, MP 170, MP 177, MP 277, MP 377, and the early Comfort Panel generations — before TIA Portal consolidated configuration under WinCC Unified. The product's tag editor remains the central nervous system of every project: it governs data flow between controller and visualization, drives alarms, archives, and trend views, and ultimately determines how scalable a panel project becomes.

Despite the editor's mature feature set, a recurring pattern emerges when projects grow beyond approximately 200 tags: bulk-creation workflows become slow, and operations inside array-indexed (multiplexed) tag rows behave unexpectedly. This reference describes the internal data model, documents the CSV import schema, and presents field-tested workarounds for the editor's known operational boundaries — none of which require abandoning WinCC Flexible for a full TIA Portal migration unless broader code convergence is required.

Tag Editor Architecture and Data Model

The WinCC Flexible tag database is built on three abstraction layers. At the lowest level sit Connections (S7 MPI/PROFIBUS/TCP, Modbus TCP, OPC DA, Allen-Bradley DF1, Mitsubishi MC Protocol, and Modbus RTU on serial ports), which bind the panel to one or more controllers. Each connection holds Tags, which carry the data type, address, scaling, and acquisition cycle. Tags are instantiated as either scalar references or array members, where the array is created declaratively (Array count > 1) or through a pointer-driven multiplexing scheme configured under "Connections > Area Pointer."

Tag Class Scope Storage Acquisition Trigger
HMI Internal Local to panel 4-byte aligned internal memory On event only
PLC Tag (scalar) Bound to controller memory Single bit / byte / word address Cyclic or "On Demand"
PLC Tag (array) Bound to controller address space Length > 1 elements Cyclic with single read
Multiplex Tag Pointer-driven in/out Index opcode Pointer address swap
Pointer Tag Area pointer / Job mailbox Reserved address range Cyclic with priority scan

Array tags are at the heart of multiplexing: by declaring an ArrayCount of 100 on DB751.DBW0 the editor creates 100 logical tag references (indices 0..99) that resolve to consecutive addresses in the source controller. Visually a single row appears in the tag editor, but operationally the array is treated as 100 distinct symbols for alarms, trends, scripts, and the Find/Replace dialog — with the limitation that the editor itself only displays the base row at design time.

Tag Naming Rules and Constraints

Constraint Value Notes
Maximum name length 32 characters Compiler limit
Allowed characters A-Z, a-z, 0-9, _ No Unicode, no hyphens
First character A-Z or a-z Digit-leading or underscore-leading rejected
Case sensitivity Compile-time case sensitive Runtime mostly case-insensitive
Reserved prefixes @ namespace blocked System tag area
Maximum array count 32 767 elements Signed 16-bit index range
PowerTag equivalents 2 048 base; expandable via options License-dependent cap
Naming rules differ from the controller side. S7-200/300/400 allow longer mnemonics with German umlauts when configured in the STEP 7 symbol table; WinCC Flexible drops those characters during tag import and silently reports invalid rows. Pre-clean symbol tables before importing, replacing umlauts with ASCII equivalents.

Mass Tag Creation Workflows

When a project requires more than a few dozen tags the editor's row-by-row creation loop becomes the bottleneck. Three workflows are available:

  1. In-editor row creation: Designed for under ~50 tags; each row gets a fixed format of Name, PLC, Type, Address, Cycle. Painful for hundreds.
  2. CSV import: The documented bulk path. Implemented as comma- or semicolon-separated file with a header row validated on import. Supports up to ~32 000 tags per file before editor scan time becomes unwieldy.
  3. Symbol block import: Direct import from STEP 7 symbol tables (.sdf) for tags that are kept in the controller side as source of truth.

For the panel team the CSV path is normally the only viable route because STEP 7 symbols may not exist for HMI-only generated tags. Building the CSV file by hand for hundreds of tags is equally impractical, so the practical pattern is to generate the file from a script or a spreadsheet macro, then commit it under version control alongside the WinCC Flexible project file (.hmi/.fl).

CSV Import Format Specification

The CSV import obeys a fixed schema. Whitespace and case in column names are not significant, but the order of columns may vary between WinCC Flexible versions. The most widely-supported column set for WinCC Flexible 2008 SP5 is shown below.

Name;PLC;DataType;Address;Length;InitialValue;Comment;AcquisitionCycle;LinearScaling;LinearScalingBegin;LinearScalingEnd;LimitMin;LimitMax;LimitColorMin;LimitColorMax

Field semantics for a typical import file:

Column Type Description
Name String HMI tag identifier (32-char limit)
PLC String Connection reference name as defined in "Connections"
DataType Enum Bool, Byte, Int, DInt, Real, String, Word, DWord, Date_And_Time
Address String Controller reference: e.g. MW12, DB751.DBW0, DB10.DBX4.0
Length Integer Number of array elements; omit or set 1 for scalar tags
InitialValue String Literal value for resets or panel restart
Comment String Free-text description shown in tag list
AcquisitionCycle Integer (ms) Update interval; default 1000 ms
LinearScaling Boolean Use linear transform between process and HMI value
LinearScalingBegin / End Float Process range boundaries
LimitMin / LimitMax Float Alarm thresholds
LimitColorMin / Max Hex string Alarm color (BBGGRR hex format on legacy builds)

Encoding: ANSI / Windows-1252 is the safest. UTF-8 files with non-ASCII characters in comments import but conversion can mangle umlauts. Save the file with no BOM and use semicolon delimiters when the regional setting uses comma as decimal separator; otherwise the editor double-quotes the import.

Generating the CSV from a Script

Manual entry is infeasible for projects with hundreds of tags. The reliable approach is to script CSV generation. The Python snippet below produces 100 tags named VAR_KS0 through VAR_KS99, each pointing to consecutive MW addresses, ready for import into WinCC Flexible:

import csv HEADER = [ 'Name', 'PLC', 'DataType', 'Address', 'Length', 'InitialValue', 'Comment', 'AcquisitionCycle', 'LinearScaling', 'LinearScalingBegin', 'LinearScalingEnd', 'LimitMin', 'LimitMax', 'LimitColorMin', 'LimitColorMax' ] with open('mass_tags.csv', 'w', newline='', encoding='latin-1') as f: w = csv.writer(f, delimiter=';') w.writerow(HEADER) for i in range(100): w.writerow([ f'VAR_KS{i}', # Name 'PLC_1', # Connection ref 'Int', # Type f'MW{12 + 2 * i:03d}', # Address: consecutive words '1', # Scalar (no array) '0', # Initial value f'Setpoint {i}', # Comment '500', # 500 ms cycle 'False', # No scaling '0', '100', '-10', '110', '00FF0000', '00FF0000' ])
Always validate the generated CSV with WinCC Flexible's "Tag import" dialog using a small test set before scaling to thousands of rows. Error messages for malformed rows reference line numbers in the CSV file, so a 100-row sanity check is faster than a 1000-row import that fails late.

Find/Replace and Rewire Operations

The Find/Replace dialog (Edit menu > Find and Replace) supports text replacement across the tag editor's main columns. Its behavior depends on column:

Operation Name column Address column Comment column Symbol column
Find (any cell) Supported Supported Supported Supported
Replace text Supported Supported Supported Not supported in dialog
Replace address Not updated Supported Not updated Not updated
Replace on array row Applies to base name Applies to address Applies to comment Applies per element
Regular expressions Not supported Not supported Not supported Not supported

The Rewire dialog (Editor > Tags > Rewire) is a related but separate operation. It reads the Name column of each tag for matching, optionally replaces the matched name with a new name, but does not auto-update the Symbol or Address fields to follow the rename. When rewiring VARKS1 bound to MW12 to VARKS2, the address stays at MW12 in the displayed dialogue and the Reconnect button fails unless the new tag VARKS2 exists at the desired address — typically created manually or imported first.

A common workaround is to bulk-rename tags via CSV re-import rather than through the Rewire dialog: regenerate the CSV with corrected names and corrected addresses for the affected rows, then re-import. The editor does not destroy tags that retain the same name; it updates metadata for matching rows and inserts new tags for previously absent names.

Multiplexed Tag Behavior

When an array tag carries Length > 1, Find/Replace addresses only the base row. Search terms typed into the dialog hit the base address string DB751.DBW0 but do not propagate to DB751.DBW2, DB751.DBW4, etc., because internally these are array indices, not discrete name entries. Replacing DB751 with DB752 via the dialog updates only the visible base name; the index-expansion rules regenerate the substituted address only when the project is re-compiled and the array is recreated.

Where large-scale replacement inside an array is required — for instance shifting 50 variables from DB751 to DB752 as a refactor — the documented route is to delete the array, recreate it at the new address, and re-bind the graphics objects. This is destructive and time-consuming for projects with hundreds of references; the practical mitigation is to avoid tying the array base to a meaningful DB number in the source design and to reserve one DB per array element under a non-collision engine ID.

Component Object Scripting and External Access

WinCC Professional and WinCC v7 expose their graphics primitives (circles, polylines, IO fields, alarm views) over COM/DCOM so that external languages (C#, C++, VB6, PowerShell) can build or modify screens at runtime or offline. WinCC Flexible has no analogous surface. The runtime side offers a VBS interpreter; the engineering side exposes its own internal model, but no public automation interface for third-party tooling. Practical consequences:

  • No programmatic screen generator: Templates cannot be assembled from outside the engineering station. Developers rely on WinCC Flexible's faceplate "Library" feature for parameterizable graphics and must build one faceplate template per logical unit.
  • VBS limitations: The runtime VBS interpreter supports the SmartTags() and HMIRuntime.Tags collections, properties on objects (visible, x, y, width, height, text), and arithmetic. It does not support graphical-primitive creation, multi-threading, custom COM object instantiation, or filesystem traversal beyond a restricted whitelist.
  • Tag access from external clients: Limited to OPC DA 2.0 server, optionally licensed, that WinCC Flex can host. There is no DCOM automation server for tags alone.

For projects that require mass-generated faceplates (e.g. one valve faceplate per tag in a 500-valve plant) the discipline replaces what COM automation would have provided. A typical pattern: build one faceplate instance per logical unit, reference it via a multiplexer index or through direct screen navigation, and rely on the array tag mechanism to bind values. The same constraint applies to alarm class design — alarm classes are not scriptable and cannot be cloned programmatically.

Migration to TIA Portal WinCC

Siemens positions TIA Portal WinCC (also called WinCC Professional or WinCC Unified) as the formal successor. Several conversion paths exist for tags:

  1. WinCC Flexible to TIA Portal porting tool: Integrated into TIA Portal from V13 onward (recalled by menu "Project > Migrate project"). Imports .hmi/.fl files and converts tags, connections, alarms, and screens. Limitations: Comfort Panel targets migrate cleanly; older OP/TP series with firmware < a runtime baseline may require panel replacement or firmware update.
  2. CSV bridge: Export the WinCC Flexible tag list via the editor's text export (right-click > "Export"), produce a CSV matching the TIA Portal tag import schema, then re-import on the TIA side. Works for projects that must co-exist on a mixed panel fleet during phased hardware refresh.
  3. Rebuild from symbol sources: When TIA Portal is the master configuration database, build the symbol export from STEP 7 / TIA project, then drive tag imports from the symbol table rather than from the legacy CSV.
Firmware portability: panels at firmware < the migration baseline need an OS update as part of the conversion. Confirm the WinCC Flexible "OS Update" bundle is downloaded under "Panel tools" in TIA Portal before starting the porting step, because the converter refuses to migrate forward if the firmware target is missing.

Scripts and recipes do not port directly — manual rebuild is required for VBS scripts because TIA Portal WinCC uses C# scripts and WinCC Unified uses JavaScript. VBS script libraries typically need re-implementation against the TIA Portal scripting API. The official WinCC Flexible engineering manual and WinCC Professional scripting reference live under Siemens Industry Online Support; searches for "WinCC Professional Scripting" return the API entry and the runtime C# script editor help pages.

Best Practices for Scaling WinCC Flexible Projects

  1. Treat CSV imports as source of truth. Even when editing happens in the engineering station, regenerate tags via CSV and run version control (e.g. GIT) on the CSV file. This decouples tag names from any single engineer workstation.
  2. Tie array bases to placeholder DB numbers. e.g. DB900.DB10000 for an array of 200 tags. The array count carries the parameter space without giving Find/Replace unwanted footholds into real project data blocks.
  3. Use naming conventions that survive in-editor replacement. Pattern: AREA_FUNCTION_INSTANCE with single-character area codes (e.g. S_ setpoint, V_ valve, M_ motor). It keeps Find/Replace boundaries predictable and avoids accidental wildcard matches.
  4. Group tag lists by lifecycle. A reservoir of "operational" tags that change rarely belongs in one CSV; project-experimental tags live in another. Avoid centralizing so many tags that editor scan time degrades project load.
  5. Maintain a Symbol Library project (.hmi-template). Master template that downstream projects fork from; tag standardization becomes enforceable across plants and lines.
  6. Adopt checksum verification on import. After every CSV import, open the tag editor, sort by Address, and verify that no duplicates exist. Duplicate tag names cause compile errors that present as opaque messages at runtime.

Tag Editor Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Step Resolution
Replace button greyed out on Rewire dialog New tag does not exist in project Open tag editor; filtered view for new name Create empty tag, then rewire
Address shown with stray character (e.g. "M12" instead of "MW12") Reconnect passed through non-canonical form Compare displayed address with valid canonical cell Manual edit; re-import via CSV
Find/Replace does not update array row Array row carries single base address only Filter "array only" view; run Find on Address column Rebuild the array or refactor to scalar per-row
Bulk paste lost namespace prefix Excel clipboard inserts row above selected when misanchored Test with single row before mass paste Paste into ancillary Notepad first, then copy structured rows
CSV import fails silently in row 414 Encoding mismatch (UTF-8 with BOM vs ANSI) Open CSV with hex viewer; check first three bytes Save without BOM, ANSI / Latin-1
Tag compiles but value freezes at last good value Acquisition cycle too long for trend view scan Open Trend Properties; cross-check tag cycle Reduce cycle (e.g. 500 ms)
"Tag not present in PLC" alarm on every scan Wrong OPC partner or connection cleared PC station check; verify connection partner in WinCC Flex Re-create connection; redeploy panel image
Multiplex index reads wrong element Index opcode direction reversed (Index-In vs Index-Out) Inspect pointer tag properties Swap pointer direction; recompile
OPC DA server unreachable from third-party client OPC tunneling or DCOM permissions not configured Test with OPC DA 2.0 sample client Configure dcomcnfg; install OPC Core Components

Specifications Reference

Item Value / Limit
Supported panel firmware (latest release) WinCC Flexible 2008 SP5
Tag count per project (PowerTag equivalent) 2 048 base; expandable via options to 4 096+
Maximum array count per tag 32 767 elements
CSV import row practical limit ~32 000 rows per file before editor scan slows noticeably
Runtime VBS execution scope Tags, IO field values, simple object properties, arithmetic
External automation interfaces OPC DA 2.0 (optional license)
OPC XML / UA exports Not in WinCC Flex; replace with TIA Portal WinCC
Multiplexing opcode bit width 16-bit signed
Pointer types Area pointer, Job Mailbox, Coordination, Data record, Screen number, Date/Time
Default acquisition cycle 1000 ms
Supported data types Bool, Byte, Word, DWord, Int, DInt, Real, String, Date_And_Time
VBS function extensions PlotReference, TraceMessage, ShowLogonDialog, ActivateScreen, etc.
Screen object count limit Panel-dependent; Comfort Panels ~80 000 objects
License categories WinCC Flex Mini, Compact, Standard, Professional + panel-bound runtime

Why does the Rewire dialog not update all columns when I rename a tag?

Rewire operates on the Name column only by design. Address, Symbol, and Comment fields remain on the original value unless manually edited. To drive a full rename, regenerate the affected rows in a CSV file with both the new name and new address, then re-import — the matching logic updates the metadata of existing tags without deleting them and inserts new tags for previously absent names.

How do I bulk-create tags with sequential DB addresses such as DB751.DBW0, DB751.DBW2, ...?

Build the CSV import file with each row pinned to a different absolute DB-word address rather than using the in-editor array count. The array feature expands one declared row into multiple internal tag indices but ties them to the same base DB number, which collapses Find/Replace scope inside the row. Per-row addresses give independent visibility in the editor and the Find dialog.

Can WinCC Flexible screens be modified from external code (C#, C++, VB)?

No. WinCC Flexible does not expose a graphics automation interface. WinCC Professional and WinCC Unified do, but migration is required when this feature is needed. Until migration is complete, only the optional OPC DA 2.0 server is accessible from external clients, and that server exposes tag data, not graphics.

What is the recommended path for migrating a WinCC Flexible project to TIA Portal?

Use the TIA Portal porting tool (TIA Portal V13 onward) for an initial automated migration via "Project > Migrate project." Expect manual re-implementation for VBS scripts because TIA Portal WinCC scripting is C#, and WinCC Unified uses JavaScript — both differ syntactically and in capability from WinCC Flexible VBS. Verify panel firmware compatibility before starting; pre-existing OP-series panels may need hardware replacement or firmware update.

Does WinCC Flexible support regular expressions in Find/Replace?

No. WinCC Flexible performs literal text replacement only — the dialog does not implement any pattern language. For arbitrary matches (e.g. changing all KS\d+ tags to KV_\d+), export the tag list to CSV, perform the pattern-based rename in a text editor or a script, then re-import the corrected file.

Back to blog