An OPC UA historian that handles the hard parts

Certificates, security policies, server limits and reconnects are where OPC UA logging goes wrong. Vault deals with each of them and tells you in plain words what it did.

Connect with security on

Type the endpoint, press Discover, and Vault asks the server what it offers and picks the strongest Sign & Encrypt policy. Trust works both ways from the same screen: accept the PLC's certificate in one click, and download Vault's certificate with the steps for loading it into TIA Portal or the PLCnext web page.

When the server refuses, Vault translates the status code into the PLC's terms. BadSecurityChecksFailed becomes "the CPU refused Vault's certificate: add it under trusted clients and download to the CPU".

Vault's connection step: an OPC UA endpoint, the security chosen after discovery, and the result of testing the connection.

What Vault does on the wire

For the engineer checking whether it will behave on a production controller.

Subscriptions
Monitored items in batches of 500 per subscription; the server's limits on items, publishing and sampling are read, negotiated and reported in a sentence instead of failing silently.
Rates
A publishing interval per source and a sampling interval per signal or per folder, down to what the server allows. Server-side deadband is used where the server supports it, with a fallback to Vault's own.
Timestamps
Source, server or local time per source. Values re-sent after a reconnect are re-stamped consistently and flagged, so they never push genuine later samples out.
Reconnects
Sequence numbers are tracked per subscription. After a dropped link Vault resumes within a second, asks the server to republish anything missing and marks what it no longer holds.
Status codes
OPC UA status codes map to stored quality: good, uncertain or bad, with the reason kept. Bad values are a gap in the trend, not a zero.
Security
None, Sign, Sign & Encrypt with Basic256Sha256, Aes128_Sha256_RsaOaep or Aes256_Sha256_RsaPss. "No security" has to be confirmed twice when the server offers better. User names and passwords are stored encrypted by Windows.
Browsing
The server's address space as folders with counts and Select all at every level. Signals that cannot be stored (text, structures) are greyed out with the reason.

Siemens S7-1500

Vault ships with a step-by-step guide for the S7-1500's built-in OPC UA server: enabling it, the runtime licence, making variables visible, trusting Vault's certificate in TIA Portal and the limits on monitored items by CPU and firmware.

Read: Logging an S7-1500 over OPC UA

Phoenix Contact PLCnext

A matching guide for PLCnext controllers such as the AXC F 3152: the OPC UA server settings in PLCnext Engineer, the security policies current firmware offers, and where to put Vault's certificate in the web-based management.

OPC UA terms in the glossary

See Vault on your own plant

Early access sites get the full product, direct help from engineering, and their first site licence for £1,995 instead of £2,495.