Overview of WinCC Flexible Tag Management
WinCC Flexible ES is the Siemens HMI engineering suite released in 2005 and maintained through WinCC Flexible 2008 SP5. It configures the SIMATIC HMI panel family — OP 73 micro panels, OP 77A/B, TP 170A/B, TP 177A/B, TP 277, MP 170, MP 177, MP 277, MP 377, and the early Comfort Panel generations — before TIA Portal consolidated configuration under WinCC Unified. The product's tag editor remains the central nervous system of every project: it governs data flow between controller and visualization, drives alarms, archives, and trend views, and ultimately determines how scalable a panel project becomes.
Despite the editor's mature feature set, a recurring pattern emerges when projects grow beyond approximately 200 tags: bulk-creation workflows become slow, and operations inside array-indexed (multiplexed) tag rows behave unexpectedly. This reference describes the internal data model, documents the CSV import schema, and presents field-tested workarounds for the editor's known operational boundaries — none of which require abandoning WinCC Flexible for a full TIA Portal migration unless broader code convergence is required.
Tag Editor Architecture and Data Model
The WinCC Flexible tag database is built on three abstraction layers. At the lowest level sit Connections (S7 MPI/PROFIBUS/TCP, Modbus TCP, OPC DA, Allen-Bradley DF1, Mitsubishi MC Protocol, and Modbus RTU on serial ports), which bind the panel to one or more controllers. Each connection holds Tags, which carry the data type, address, scaling, and acquisition cycle. Tags are instantiated as either scalar references or array members, where the array is created declaratively (Array count > 1) or through a pointer-driven multiplexing scheme configured under "Connections > Area Pointer."
| Tag Class | Scope | Storage | Acquisition Trigger |
|---|---|---|---|
| HMI Internal | Local to panel | 4-byte aligned internal memory | On event only |
| PLC Tag (scalar) | Bound to controller memory | Single bit / byte / word address | Cyclic or "On Demand" |
| PLC Tag (array) | Bound to controller address space | Length > 1 elements | Cyclic with single read |
| Multiplex Tag | Pointer-driven in/out | Index opcode | Pointer address swap |
| Pointer Tag | Area pointer / Job mailbox | Reserved address range | Cyclic with priority scan |
Array tags are at the heart of multiplexing: by declaring an ArrayCount of 100 on DB751.DBW0 the editor creates 100 logical tag references (indices 0..99) that resolve to consecutive addresses in the source controller. Visually a single row appears in the tag editor, but operationally the array is treated as 100 distinct symbols for alarms, trends, scripts, and the Find/Replace dialog — with the limitation that the editor itself only displays the base row at design time.
Tag Naming Rules and Constraints
| Constraint | Value | Notes |
|---|---|---|
| Maximum name length | 32 characters | Compiler limit |
| Allowed characters | A-Z, a-z, 0-9, _ | No Unicode, no hyphens |
| First character | A-Z or a-z | Digit-leading or underscore-leading rejected |
| Case sensitivity | Compile-time case sensitive | Runtime mostly case-insensitive |
| Reserved prefixes |
@ namespace blocked |
System tag area |
| Maximum array count | 32 767 elements | Signed 16-bit index range |
| PowerTag equivalents | 2 048 base; expandable via options | License-dependent cap |
Mass Tag Creation Workflows
When a project requires more than a few dozen tags the editor's row-by-row creation loop becomes the bottleneck. Three workflows are available:
- In-editor row creation: Designed for under ~50 tags; each row gets a fixed format of Name, PLC, Type, Address, Cycle. Painful for hundreds.
- CSV import: The documented bulk path. Implemented as comma- or semicolon-separated file with a header row validated on import. Supports up to ~32 000 tags per file before editor scan time becomes unwieldy.
- Symbol block import: Direct import from STEP 7 symbol tables (.sdf) for tags that are kept in the controller side as source of truth.
For the panel team the CSV path is normally the only viable route because STEP 7 symbols may not exist for HMI-only generated tags. Building the CSV file by hand for hundreds of tags is equally impractical, so the practical pattern is to generate the file from a script or a spreadsheet macro, then commit it under version control alongside the WinCC Flexible project file (.hmi/.fl).
CSV Import Format Specification
The CSV import obeys a fixed schema. Whitespace and case in column names are not significant, but the order of columns may vary between WinCC Flexible versions. The most widely-supported column set for WinCC Flexible 2008 SP5 is shown below.
Name;PLC;DataType;Address;Length;InitialValue;Comment;AcquisitionCycle;LinearScaling;LinearScalingBegin;LinearScalingEnd;LimitMin;LimitMax;LimitColorMin;LimitColorMaxField semantics for a typical import file:
| Column | Type | Description |
|---|---|---|
| Name | String | HMI tag identifier (32-char limit) |
| PLC | String | Connection reference name as defined in "Connections" |
| DataType | Enum | Bool, Byte, Int, DInt, Real, String, Word, DWord, Date_And_Time |
| Address | String | Controller reference: e.g. MW12, DB751.DBW0, DB10.DBX4.0 |
| Length | Integer | Number of array elements; omit or set 1 for scalar tags |
| InitialValue | String | Literal value for resets or panel restart |
| Comment | String | Free-text description shown in tag list |
| AcquisitionCycle | Integer (ms) | Update interval; default 1000 ms |
| LinearScaling | Boolean | Use linear transform between process and HMI value |
| LinearScalingBegin / End | Float | Process range boundaries |
| LimitMin / LimitMax | Float | Alarm thresholds |
| LimitColorMin / Max | Hex string | Alarm color (BBGGRR hex format on legacy builds) |
Encoding: ANSI / Windows-1252 is the safest. UTF-8 files with non-ASCII characters in comments import but conversion can mangle umlauts. Save the file with no BOM and use semicolon delimiters when the regional setting uses comma as decimal separator; otherwise the editor double-quotes the import.
Generating the CSV from a Script
Manual entry is infeasible for projects with hundreds of tags. The reliable approach is to script CSV generation. The Python snippet below produces 100 tags named VAR_KS0 through VAR_KS99, each pointing to consecutive MW addresses, ready for import into WinCC Flexible:
import csv
HEADER = [
'Name', 'PLC', 'DataType', 'Address', 'Length', 'InitialValue',
'Comment', 'AcquisitionCycle', 'LinearScaling', 'LinearScalingBegin',
'LinearScalingEnd', 'LimitMin', 'LimitMax', 'LimitColorMin',
'LimitColorMax'
]
with open('mass_tags.csv', 'w', newline='', encoding='latin-1') as f:
w = csv.writer(f, delimiter=';')
w.writerow(HEADER)
for i in range(100):
w.writerow([
f'VAR_KS{i}', # Name
'PLC_1', # Connection ref
'Int', # Type
f'MW{12 + 2 * i:03d}', # Address: consecutive words
'1', # Scalar (no array)
'0', # Initial value
f'Setpoint {i}', # Comment
'500', # 500 ms cycle
'False', # No scaling
'0', '100',
'-10', '110',
'00FF0000', '00FF0000'
])
Find/Replace and Rewire Operations
The Find/Replace dialog (Edit menu > Find and Replace) supports text replacement across the tag editor's main columns. Its behavior depends on column:
| Operation | Name column | Address column | Comment column | Symbol column |
|---|---|---|---|---|
| Find (any cell) | Supported | Supported | Supported | Supported |
| Replace text | Supported | Supported | Supported | Not supported in dialog |
| Replace address | Not updated | Supported | Not updated | Not updated |
| Replace on array row | Applies to base name | Applies to address | Applies to comment | Applies per element |
| Regular expressions | Not supported | Not supported | Not supported | Not supported |
The Rewire dialog (Editor > Tags > Rewire) is a related but separate operation. It reads the Name column of each tag for matching, optionally replaces the matched name with a new name, but does not auto-update the Symbol or Address fields to follow the rename. When rewiring VARKS1 bound to MW12 to VARKS2, the address stays at MW12 in the displayed dialogue and the Reconnect button fails unless the new tag VARKS2 exists at the desired address — typically created manually or imported first.
Multiplexed Tag Behavior
When an array tag carries Length > 1, Find/Replace addresses only the base row. Search terms typed into the dialog hit the base address string DB751.DBW0 but do not propagate to DB751.DBW2, DB751.DBW4, etc., because internally these are array indices, not discrete name entries. Replacing DB751 with DB752 via the dialog updates only the visible base name; the index-expansion rules regenerate the substituted address only when the project is re-compiled and the array is recreated.
Where large-scale replacement inside an array is required — for instance shifting 50 variables from DB751 to DB752 as a refactor — the documented route is to delete the array, recreate it at the new address, and re-bind the graphics objects. This is destructive and time-consuming for projects with hundreds of references; the practical mitigation is to avoid tying the array base to a meaningful DB number in the source design and to reserve one DB per array element under a non-collision engine ID.
Component Object Scripting and External Access
WinCC Professional and WinCC v7 expose their graphics primitives (circles, polylines, IO fields, alarm views) over COM/DCOM so that external languages (C#, C++, VB6, PowerShell) can build or modify screens at runtime or offline. WinCC Flexible has no analogous surface. The runtime side offers a VBS interpreter; the engineering side exposes its own internal model, but no public automation interface for third-party tooling. Practical consequences:
- No programmatic screen generator: Templates cannot be assembled from outside the engineering station. Developers rely on WinCC Flexible's faceplate "Library" feature for parameterizable graphics and must build one faceplate template per logical unit.
-
VBS limitations: The runtime VBS interpreter supports the
SmartTags()andHMIRuntime.Tagscollections, properties on objects (visible, x, y, width, height, text), and arithmetic. It does not support graphical-primitive creation, multi-threading, custom COM object instantiation, or filesystem traversal beyond a restricted whitelist. - Tag access from external clients: Limited to OPC DA 2.0 server, optionally licensed, that WinCC Flex can host. There is no DCOM automation server for tags alone.
For projects that require mass-generated faceplates (e.g. one valve faceplate per tag in a 500-valve plant) the discipline replaces what COM automation would have provided. A typical pattern: build one faceplate instance per logical unit, reference it via a multiplexer index or through direct screen navigation, and rely on the array tag mechanism to bind values. The same constraint applies to alarm class design — alarm classes are not scriptable and cannot be cloned programmatically.
Migration to TIA Portal WinCC
Siemens positions TIA Portal WinCC (also called WinCC Professional or WinCC Unified) as the formal successor. Several conversion paths exist for tags:
- WinCC Flexible to TIA Portal porting tool: Integrated into TIA Portal from V13 onward (recalled by menu "Project > Migrate project"). Imports .hmi/.fl files and converts tags, connections, alarms, and screens. Limitations: Comfort Panel targets migrate cleanly; older OP/TP series with firmware < a runtime baseline may require panel replacement or firmware update.
- CSV bridge: Export the WinCC Flexible tag list via the editor's text export (right-click > "Export"), produce a CSV matching the TIA Portal tag import schema, then re-import on the TIA side. Works for projects that must co-exist on a mixed panel fleet during phased hardware refresh.
- Rebuild from symbol sources: When TIA Portal is the master configuration database, build the symbol export from STEP 7 / TIA project, then drive tag imports from the symbol table rather than from the legacy CSV.
Scripts and recipes do not port directly — manual rebuild is required for VBS scripts because TIA Portal WinCC uses C# scripts and WinCC Unified uses JavaScript. VBS script libraries typically need re-implementation against the TIA Portal scripting API. The official WinCC Flexible engineering manual and WinCC Professional scripting reference live under Siemens Industry Online Support; searches for "WinCC Professional Scripting" return the API entry and the runtime C# script editor help pages.
Best Practices for Scaling WinCC Flexible Projects
- Treat CSV imports as source of truth. Even when editing happens in the engineering station, regenerate tags via CSV and run version control (e.g. GIT) on the CSV file. This decouples tag names from any single engineer workstation.
- Tie array bases to placeholder DB numbers. e.g. DB900.DB10000 for an array of 200 tags. The array count carries the parameter space without giving Find/Replace unwanted footholds into real project data blocks.
-
Use naming conventions that survive in-editor replacement. Pattern:
AREA_FUNCTION_INSTANCEwith single-character area codes (e.g.S_setpoint,V_valve,M_motor). It keeps Find/Replace boundaries predictable and avoids accidental wildcard matches. - Group tag lists by lifecycle. A reservoir of "operational" tags that change rarely belongs in one CSV; project-experimental tags live in another. Avoid centralizing so many tags that editor scan time degrades project load.
- Maintain a Symbol Library project (.hmi-template). Master template that downstream projects fork from; tag standardization becomes enforceable across plants and lines.
- Adopt checksum verification on import. After every CSV import, open the tag editor, sort by Address, and verify that no duplicates exist. Duplicate tag names cause compile errors that present as opaque messages at runtime.
Tag Editor Troubleshooting Matrix
| Symptom | Likely Root Cause | Diagnostic Step | Resolution |
|---|---|---|---|
| Replace button greyed out on Rewire dialog | New tag does not exist in project | Open tag editor; filtered view for new name | Create empty tag, then rewire |
| Address shown with stray character (e.g. "M12" instead of "MW12") | Reconnect passed through non-canonical form | Compare displayed address with valid canonical cell | Manual edit; re-import via CSV |
| Find/Replace does not update array row | Array row carries single base address only | Filter "array only" view; run Find on Address column | Rebuild the array or refactor to scalar per-row |
| Bulk paste lost namespace prefix | Excel clipboard inserts row above selected when misanchored | Test with single row before mass paste | Paste into ancillary Notepad first, then copy structured rows |
| CSV import fails silently in row 414 | Encoding mismatch (UTF-8 with BOM vs ANSI) | Open CSV with hex viewer; check first three bytes | Save without BOM, ANSI / Latin-1 |
| Tag compiles but value freezes at last good value | Acquisition cycle too long for trend view scan | Open Trend Properties; cross-check tag cycle | Reduce cycle (e.g. 500 ms) |
| "Tag not present in PLC" alarm on every scan | Wrong OPC partner or connection cleared | PC station check; verify connection partner in WinCC Flex | Re-create connection; redeploy panel image |
| Multiplex index reads wrong element | Index opcode direction reversed (Index-In vs Index-Out) | Inspect pointer tag properties | Swap pointer direction; recompile |
| OPC DA server unreachable from third-party client | OPC tunneling or DCOM permissions not configured | Test with OPC DA 2.0 sample client | Configure dcomcnfg; install OPC Core Components |
Specifications Reference
| Item | Value / Limit |
|---|---|
| Supported panel firmware (latest release) | WinCC Flexible 2008 SP5 |
| Tag count per project (PowerTag equivalent) | 2 048 base; expandable via options to 4 096+ |
| Maximum array count per tag | 32 767 elements |
| CSV import row practical limit | ~32 000 rows per file before editor scan slows noticeably |
| Runtime VBS execution scope | Tags, IO field values, simple object properties, arithmetic |
| External automation interfaces | OPC DA 2.0 (optional license) |
| OPC XML / UA exports | Not in WinCC Flex; replace with TIA Portal WinCC |
| Multiplexing opcode bit width | 16-bit signed |
| Pointer types | Area pointer, Job Mailbox, Coordination, Data record, Screen number, Date/Time |
| Default acquisition cycle | 1000 ms |
| Supported data types | Bool, Byte, Word, DWord, Int, DInt, Real, String, Date_And_Time |
| VBS function extensions | PlotReference, TraceMessage, ShowLogonDialog, ActivateScreen, etc. |
| Screen object count limit | Panel-dependent; Comfort Panels ~80 000 objects |
| License categories | WinCC Flex Mini, Compact, Standard, Professional + panel-bound runtime |
Why does the Rewire dialog not update all columns when I rename a tag?
Rewire operates on the Name column only by design. Address, Symbol, and Comment fields remain on the original value unless manually edited. To drive a full rename, regenerate the affected rows in a CSV file with both the new name and new address, then re-import — the matching logic updates the metadata of existing tags without deleting them and inserts new tags for previously absent names.
How do I bulk-create tags with sequential DB addresses such as DB751.DBW0, DB751.DBW2, ...?
Build the CSV import file with each row pinned to a different absolute DB-word address rather than using the in-editor array count. The array feature expands one declared row into multiple internal tag indices but ties them to the same base DB number, which collapses Find/Replace scope inside the row. Per-row addresses give independent visibility in the editor and the Find dialog.
Can WinCC Flexible screens be modified from external code (C#, C++, VB)?
No. WinCC Flexible does not expose a graphics automation interface. WinCC Professional and WinCC Unified do, but migration is required when this feature is needed. Until migration is complete, only the optional OPC DA 2.0 server is accessible from external clients, and that server exposes tag data, not graphics.
What is the recommended path for migrating a WinCC Flexible project to TIA Portal?
Use the TIA Portal porting tool (TIA Portal V13 onward) for an initial automated migration via "Project > Migrate project." Expect manual re-implementation for VBS scripts because TIA Portal WinCC scripting is C#, and WinCC Unified uses JavaScript — both differ syntactically and in capability from WinCC Flexible VBS. Verify panel firmware compatibility before starting; pre-existing OP-series panels may need hardware replacement or firmware update.
Does WinCC Flexible support regular expressions in Find/Replace?
No. WinCC Flexible performs literal text replacement only — the dialog does not implement any pattern language. For arbitrary matches (e.g. changing all KS\d+ tags to KV_\d+), export the tag list to CSV, perform the pattern-based rename in a text editor or a script, then re-import the corrected file.