WinCC Raw Data Type Floating-Point Array OPCScout uint8 Fix

David Krause13 min read
OPC / OPC UASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

WinCC Raw Data Type Floating-Point Array Showing as uint8 in OPCScout — Root Cause and Field-Proven Fix

Engineers integrating Siemens WinCC with a SIMATIC S7-400 over an OPC channel routinely define high-density process data — for example 126-element 32-bit floating-point arrays — as a single raw data type tag. The tag behaves correctly inside the WinCC runtime and inside the WinCC tag manager: the HMI shows the correct decimal values, alarming works, and the archive writes the correct IEEE-754 representation to disk. The moment a third-party OPC client such as Siemens OPCScout or Matrikon OPCExplorer browses the same address space, however, the same tag surfaces as a uint8[] byte array of length 504 instead of a float[] array of length 126. This article documents the root cause, the byte-level mathematics, the OPC DA/UA specification interaction, the OPCScout version compatibility matrix, and the field-verified remediation paths.

1. Problem Summary

Symptom Observed Value Expected Value
WinCC tag type (Tag Management) Raw data type, 504 bytes Raw data type, 504 bytes
WinCC address property 32-Bit Floating-Point Number Array 32-Bit Floating-Point Number Array
Array element count (logical) 126 elements 126 elements
OPCScout presentation uint8[] length 504 float[] length 126
Matrikon OPCExplorer presentation uint8[] length 504 float[] length 126
Consumed via WinCC OLE-DB / CSV export Correct floats Correct floats
Consumed via Excel OPC-DA automation Wrong (byte stream) Float array

The size ratio is the diagnostic fingerprint: 126 × 4 = 504. The 32-bit IEEE-754 float is being delivered to the OPC client as a flat octet stream, and the OPC client correctly declares it as unsigned char[] (or uint8[] in OPC-UA browse notation) because the OPC server itself publishes no structured type information for the raw data tag.

2. Root Cause Analysis

2.1 What "Raw Data Type" Means in WinCC

According to the official Siemens documentation, a raw data tag in WinCC is a tag whose format and length are not fixed. The tag is a transparent byte container whose internal structure is meaningful only to the application that interprets it. WinCC stores the tag in a single OPC item, but the OPC server does not advertise a structured data type; it only advertises the byte length. Per the TIA Portal reference for RT Professional, raw data tags are typed as VT_ARRAY | VT_UI1 in classic OPC Data Access 2.0/3.0 terms — an array of unsigned bytes. The WinCC address property dialog lets the engineer label the tag as a 32-bit floating-point number array, but that label is local to WinCC and is not propagated into the OPC namespace.

Reference: Raw data tags (RT Professional) — TIA Portal Help

2.2 OPC Data Access Type Advertisement

The WinCC OPC-DA server publishes the canonical datatype as VT_UI1 for any raw data tag. The variant VT_UI1 with an array flag maps to the OPC canonical datatype OPC_UI1 (unsigned 8-bit integer). The full byte length is set in the ItemDef as 504 for the 126-element float array. There is no way for a generic OPC-DA client to know that the bytes are intended to be regrouped into 32-bit floats. The OPC-DA 2.0 specification does not carry a sub-array element type, so a third-party client browsing the address space will, by definition, see an unsigned byte array.

2.3 OPC UA Equivalent

If the WinCC project is exposed through an OPC-UA wrapper (Simatic Net OPC-UA server, or a third-party UA gateway), the published DataType node for the same raw data item resolves to ByteString or UInt8[] under the OPC-UA namespace http://opcfoundation.org/UA/. UA's Variant type system does include a 32-bit float scalar, but it is not bound to the item. Just like DA, UA carries the raw octets; the structuring rule must be provided by either the configuration tool or the consuming application.

2.4 Why WinCC Internal Clients Read Correctly

WinCC's own HMI runtime, archive, and the WinCC OLE-DB provider all know the configured raw data layout because they read the project file directly. They interpret the 504-byte payload as 126 IEEE-754 single-precision values, perform byte-order conversion if needed, and present the result. Third-party clients do not have access to that project metadata — they only see what the OPC server publishes — so they default to the safe interpretation of an unsigned byte array.

3. Byte-Level Mathematics of the Defect

For a 126-element IEEE-754 single-precision float array the byte count is:

Bytes = Elements × sizeof(float32)
Bytes = 126 × 4
Bytes = 504 octets

The reported uint8[] length of 504 confirms the byte count is correct; only the interpretation is wrong. Byte-order representation is little-endian on every S7-400 CPU and on every WinCC variant (WinCC V7.x and WinCC Professional / TIA Portal V16–V21). The standard conversion to recover the float stream is:

for (int i = 0; i < 504; i += 4)
{
    uint32_t raw = (uint32_t)buffer[i]
                 | ((uint32_t)buffer[i+1] << 8)
                 | ((uint32_t)buffer[i+2] << 16)
                 | ((uint32_t)buffer[i+3] << 24);
    float    value;
    memcpy(&value, &raw, 4);
    floats[i / 4] = value;
}

The IEC 61131-3 REAL type on the S7-400 is binary-compatible with IEEE-754 single precision, so no NaN handling, no endian-swap helper, and no scaling is required beyond the byte regrouping above.

Note on byte order: S7-400, S7-300, S7-1200, and S7-1500 all store REAL in little-endian. If the array originates from a third-party Modbus/Profibus slave with big-endian register order, swap the byte pairs (word-swap) before reassembly.

4. OPCScout Version Compatibility

OPCScout Version Release Year Raw Data Display Float-Array Hint Available
V6.4 (shipped with SIMATIC NET 2007) 2007 uint8[] No
V10 (shipped with SIMATIC NET 2008 HP) 2009 uint8[] with byte-grid No
V10 SP2 (with WinCC V7.0) 2010 uint8[] No
V12 (SIMATIC NET 2010) 2011 uint8[] No
V13 (TIA Portal V13) 2014 uint8[] No
V15 / V15.1 (TIA Portal V15/V15.1) 2017–2018 uint8[] No
V16 / V17 (TIA Portal V16/V17) 2019–2021 uint8[] No
V18 / V19 / V20 / V21 (current) 2022–2026 uint8[] No

Every released OPCScout version, including the long-standing V10, presents raw data tags as uint8[]. The forum-cited recommendation to "try OPCScout V10" is rooted in a slightly better raw-data grid in that version, but it does not change the canonical datatype. The correct path forward is to restructure the WinCC tag — not to chase a viewer.

5. Solution Path A — Replace the Raw Data Tag with Structured Float Tags (Recommended)

5.1 Procedure

  1. Open the WinCC Explorer (WinCC V7) or the TIA Portal project that hosts the HMI station.
  2. Open Tag Management and locate the existing raw data tag (e.g. ProcessFloats_126).
  3. Delete the raw data tag.
  4. Create 126 individual tags, one per element. Configure each as 32-bit floating-point number and set the data type on the PLC side to REAL.
  5. Bind each new tag to the same S7 DB but to a distinct byte offset. Element n lives at byte offset (n × 4) within the DB.
  6. Assign the same OPC-DA name pattern as before if the consuming application expects a fixed prefix (e.g. Channel1\.ProcessFloats_126[0], Channel1\.ProcessFloats_126[1], …, Channel1\.ProcessFloats_126[125]).
  7. If the consumer still needs a single OPC item, expose the DB block as a structured tag using WinCC Tag Simulator or a SIMATIC Net Symbolic connection so the OPC server publishes a structured REAL[126] definition.
  8. Recompile the OS, download to the runtime, and restart the WinCC data manager.

5.2 Verification

  1. Launch OPCScout and connect to OPC.SimaticNET.DA (or the configured WinCC OPC-DA server).
  2. Browse the new tag ProcessFloats_126[0]. The Canonical Datatype column must read VT_R4 (OPC_R4) — not VT_UI1.
  3. Read the value and compare against the value seen inside the S7-PLCSIM or the online watch table of STEP 7.
  4. If the array is consumed by a UA client, browse the UA address space and confirm the DataType node resolves to Float (NodeId ns=0;i=10) or a structured Float[].

6. Solution Path B — Keep the Raw Data Tag, Convert on the Client

If restructuring the WinCC project is not acceptable (e.g. project is in validation, the consumer is a sealed Excel macro, or the SCADA already speaks raw bytes), convert on the client side.

6.1 C# / .NET (OPC Automation Wrapper)

OpcServer srv = new OpcServer();
srv.Connect("OPC.SimaticNET.DA");
OpcGroup grp = srv.OPCGroups.Add("Raw");
OpcItem itm = grp.OPCItems.AddItem(
    "Channel1.ProcessFloats_126",
    12345);
grp.IsActive = true;
grp.IsSubscribed = true;
object value;
short quality;
DateTime timestamp;
grp.SyncRead((short)OPC_DATASOURCE.OPC_DS_DEVICE,
             1, ref new[] { itm.ServerHandle },
             out value, out quality, out timestamp);
byte[] buffer = (byte[])value;
float[] floats = new float[126];
Buffer.BlockCopy(buffer, 0, floats, 0, 504);
for (int i = 0; i < 126; i++)
{
    Console.WriteLine($"f[{i}] = {floats[i]:F3}");
}

6.2 Python (OpenOPC + struct)

import OpenOPC, struct
opc = OpenOPC.client()
opc.connect("OPC.SimaticNET.DA")
raw = opc.read("Channel1.ProcessFloats_126")[0]
fmt = "<" + "f" * 126         # little-endian, 126 floats
floats = struct.unpack(fmt, raw)
for i, v in enumerate(floats):
    print(f"f[{i}] = {v:.3f}")

6.3 Excel VBA (OPC-DA Automation)

Sub ReadFloatArray()
    Dim srv As OPCServer, grp As OPCGroup, itm As OPCItem
    Set srv = New OPCServer
    srv.Connect "OPC.SimaticNET.DA"
    Set grp = srv.OPCGroups.Add("Raw")
    Set itm = grp.OPCItems.AddItem("Channel1.ProcessFloats_126", 1)
    grp.IsActive = True
    grp.SyncRead OPCCache, 1, itm, values, errors, qualities, t
    Dim buf() As Byte
    buf = values(0)
    ReDim floats(1 To 126) As Single
    CopyMemory floats(1), buf(0), 504
    Sheet1.Range("A1").Resize(126).Value = _
        WorksheetFunction.Transpose(floats)
End Sub
Excel caveat: the CopyMemory API call requires PtrSafe declaration on 64-bit Office. The Declare line must include PtrSafe and use LongPtr for the destination argument.

7. Solution Path C — Use an OPC-UA Wrapper with Custom DataType

Modern UA servers — including the Simatic Net OPC-UA server shipped with TIA Portal V16 and later — allow the engineer to publish a custom structured DataType over an underlying raw byte stream. The wrapper decomposes the 504-byte payload into a published Float[126] UA variable. The consuming client then sees a structured array directly, no client-side byte regrouping required. The same capability is offered by third-party DA-to-UA gateways such as the Kepware Siemens TCP/IP Ethernet driver with the Advanced Tags plugin enabled.

For an S7-1500 (or S7-400 with suitable firmware) a cleaner alternative is to expose a PLC Data Type (UDT) or a STRUCT directly. The OPC-UA server maps the UDT to a UA structure, and each UDT element surfaces as a typed UA variable. STRUCT elements are mapped element-wise; arrays of REAL map to Float[] without the raw-byte detour. Reference the S7-1500 OPC-UA server manual for the full data-type mapping table.

8. OPC Server Selection — When to Migrate from WinCC OPC-DA to SIMATIC NET OPC-UA

Criterion WinCC OPC-DA SIMATIC NET OPC-UA
Raw data type support Yes (as uint8[]) Yes (as ByteString)
Structured float array Not native Native via UDT/STRUCT
End-to-end type safety No Yes (UA DataType node)
Excel / .NET client Possible, requires conversion Native float[]
Firewall friendliness DCOM — high friction HTTPS / TCP — low friction
Recommended for new projects No Yes

9. Matrikon OPCExplorer Specific Behavior

Matrikon OPCExplorer exhibits the exact same uint8[] presentation. The browser pane shows Canonical Datatype: VT_UI1 (Unsigned 8-bit integer) and the ItemID points to the WinCC tag name. Double-clicking the item opens the Item Properties dialog where the EU Type field is blank because no engineering-unit information is published. To validate the value as a float:

  1. Drag the item into the Data View pane.
  2. Right-click the cell → Convert → To Float Array.
  3. Set element count to 126 and byte order to Little-Endian.
  4. The conversion is local to OPCExplorer; the underlying OPC server still publishes uint8[].

10. Verification Checklist

# Check Pass Criterion
1 OPCScout canonical datatype VT_R4 for structured tags; VT_UI1 only if raw data is intentional
2 Value matches STEP 7 watch table Bit-exact match on at least 5 known values
3 Byte count 504 bytes for 126 elements; 4 bytes per REAL
4 Endianness Little-endian on S7-400 / S7-1500
5 Alarm + archive round-trip Values land in the WinCC archive database correctly
6 UA DataType (if UA) Float NodeId i=10, or structured Float[]
7 Excel consumption Cells show decimal float, not hex byte stream
8 Client CPU load No measurable increase after the restructure

11. Edge Cases and Field-Proven Caveats

11.1 DB Optimized Access on S7-1200 / S7-1500

If the source DB is configured with Optimized block access and the consuming tool is the legacy SIMATIC NET OPC-DA server, certain byte offsets may not be reachable. Switch the DB to Standard (compatible with S7-300/400) or expose the array as a PLC tag (symbolic) and access it through the SIMATIC NET OPC-UA symbolic interface.

11.2 S7-400 H/F/FH Systems

On S7-400H/F/FH redundant systems, raw data tags cross-subscribed to the standby CPU may briefly surface as zero-filled buffers during a fail-over. With structured REAL[126] tags the same behavior applies, but the S7-400H firmware (CPU 414H / 417H, FW V6.0 and later) re-syncs the data within 100 ms. Verify the H-sync time in HW Config → CPU Properties → Synchronization.

11.3 Big-Endian Modbus Slaves

When the float array is sourced from a third-party Modbus gateway (e.g. Schneider EGX300, Moxa MGate) that delivers big-endian register order, the regrouped floats will be byte-swapped. Apply a word-swap:

raw32 = ((raw32 & 0x00FF00FFu) << 8) |
        ((raw32 & 0xFF00FF00u) >> 8);

11.4 NaN and Infinity

IEEE-754 NaN (0x7FC00000) and ±Infinity (0x7F800000 / 0xFF800000) are valid in the S7-400 REAL range and are passed through unchanged. Excel will render NaN as #NUM!. The OPC DA quality word for NaN remains 0x0000 (Good); it is the engineer's responsibility to detect and handle these in the consumer.

11.5 Performance Footprint of 126 Individual Tags

Replacing one raw data tag with 126 structured tags increases the WinCC tag count and the OPC server's internal handle table. The WinCC V7 data manager handles several thousand tags per second of subscription throughput, so 126 additional tags is negligible. For arrays larger than 4 096 elements, prefer the structured REAL[n] via OPC-UA symbolic access to keep the tag count low.

12. Migration Plan for a Live System

  1. Capture a baseline of the existing raw data tag values over 24 hours using the WinCC Tag Logging export.
  2. Create the 126 structured tags in a parallel branch of the WinCC project.
  3. Add a WinCC global script that copies the raw payload into the structured tags for the duration of the cut-over.
  4. Switch the OPC consumers to the structured tag names.
  5. Compare the new structured-tag archive against the raw-data-tag archive for one full production shift.
  6. Once parity is confirmed, decommission the raw data tag and remove the copy script.
Validation impact: in GMP / FDA-regulated plants, the migration must be filed as a change control. Keep the raw data tag live (read-only) for the validation period so the historical comparison is bit-exact.

13. Frequently Asked Questions

Why does WinCC show the float correctly but OPCScout shows uint8[]?

WinCC reads the tag definition from the project file and knows the byte layout is IEEE-754 32-bit float. OPCScout only sees what the OPC server publishes, which for a raw data tag is the canonical datatype VT_UI1 (unsigned 8-bit integer array of 504 bytes). The OPC server has no mechanism to advertise the internal structure of a raw data tag, so OPCScout defaults to the byte view.

Does upgrading OPCScout to V10 or V21 fix the uint8[] problem?

No. Every released version of OPCScout, from V6.4 through V21, displays raw data tags as uint8[]. The datatype is published by the OPC server, not interpreted by the client. Upgrading OPCScout only changes the layout of the byte grid; it does not re-type the tag.

How many bytes does a 126-element float array occupy on the wire?

504 bytes. The formula is elements × 4 for IEEE-754 single precision, and 126 × 4 = 504. Confirm this by checking the Length property of the raw data tag in WinCC Tag Management — it should read 504.

Can I expose a structured REAL[126] from an S7-400 over OPC-UA?

Yes. Use the SIMATIC NET OPC-UA server (TIA Portal V16 or later) with a symbolic connection to the S7-400 DB, or migrate the array into an S7-1500 / S7-1200 UDT and expose the UDT as a UA structure. The client then browses a typed Float[] variable, no byte regrouping required.

Is the byte order big-endian or little-endian on S7-400?

Little-endian. The S7-400, S7-300, S7-1200, and S7-1500 all store REAL in little-endian. Use struct.unpack('<126f', payload) in Python or Buffer.BlockCopy on .NET to recover the float stream directly.

Will the raw data tag continue to work inside WinCC after I expose it to OPCScout?

Yes. The raw data tag is independent of the OPC client. WinCC continues to interpret the 504 bytes as 126 floats, archives them, alarms on them, and displays them in graphics. The OPC consumer problem is purely a type-advertisement issue, not a runtime issue.

Can Matrikon OPCExplorer decode the 504-byte array as floats?

Matrikon OPCExplorer presents the tag as VT_UI1 and offers a local Convert → To Float Array operation (right-click the cell). Set element count to 126 and byte order to little-endian. The conversion is purely a viewer feature; the underlying OPC server still publishes uint8[].

Back to blog