Integrations
Siemens S7 to SAP, without a script.
Bring PLC values and SAP's IDocs into the same namespace in MaestroHub, so a production count from the line and an order from SAP sit side by side with the same meaning. A pipeline can send a goods movement or production confirmation back into SAP as an IDoc, under permissions and audit.
The flow
One value, from the machine to SAP. Illustrative.
Siemens S7PLC protocolDB20.DBD0 (count)
MaestroHubLine 2 good parts · 1,240 · Good
- named, unit, quality
- origin stamped
- buffered on disk
SAPERP (IDoc)MBGMCR goods movementWhy do it with MaestroHub
More than a pipe from Siemens S7 to SAP.
SAP rejections caught
SAP's IDoc handler answers HTTP 200 even when it rejects a document; MaestroHub reads the response body, so a rejection is not mistaken for success.
The envelope filled for you
The IDoc control record is filled from the connection, removing the most common cause of rejected IDocs.
Machine to ERP under control
What a pipeline posts to SAP runs as a named identity, with every posting in the audit trail.
What lands in SAP
An example. You choose the fields in the pipeline.
| IDoc type | material | quantity | plant | movement type |
|---|---|---|---|---|
| MBGMCR | BC-2024-A | 1240 | 1000 | 101 |
Set it up in three steps
- 1
Connect Siemens S7
Add the S7 connection with the PLC's address, rack and slot, then create read functions for the data blocks you need.
- 2
Give the values meaning
Map each value to a topic in the namespace with its name, unit and schema. Quality and origin are stamped on every value.
- 3
Deliver to SAP
Use a goods-movement or production-order template; the control record is filled from the connection.
Before you start
What each side needs, from the connector documentation.
Siemens S7
- Network reach to the PLC on port 102 (ISO-on-TCP), entered as host:port.
- The CPU rack and slot from the PLC hardware configuration. Common combinations are rack 0 with slot 1 or slot 2.
- The session password, only if password protection is enabled in the PLC security settings. Maximum 8 characters.
- The DB numbers, byte offsets and data types of the values you need, for example from the TIA Portal project.
Example settings
- PLC Address
- 192.168.1.100:102
- Rack
- 0
- Slot
- 1
- Connection Type
- Programming Device (PG)
- Request Timeout (ms)
- 10000
- Idle Timeout (ms)
- 30000
SAP
- SAP ECC, S/4HANA on-premise or S/4HANA private cloud (RISE), with the /sap/bc/idoc_xml service activated in SICF. It is inactive by default.
- A service user with a non-expiring password and B_ALE_RECV authorization for the message types you send.
- Logical systems defined in BD54, and an inbound partner profile in WE20 for the MaestroHub logical system with a parameter for each message type.
- For receiving: an SM59 HTTP destination of type G pointing at the MaestroHub webhook, an XML HTTP port in WE21, and an outbound partner profile in WE20.
Example settings
- SAP Base URL
- https://<your-sap-host>:44300
- Inbound IDoc Path
- /sap/bc/idoc_xml
- SAP Client
- 100
- Authentication
- basic
- Sender Logical System (SNDPRN)
- MAESTROHUB
- Receiver Logical System (RCVPRN)
- P01CLNT100
Things to know
Pitfalls and limits the documentation calls out, so they don't surprise you on site.
Siemens S7
- Process Inputs (I) are read-only and writes to them are rejected. CHAR, STRING, WSTRING and the time and counter types can be written to DBs only, not to memory areas.
- For STRING and WSTRING, Size must be the declared maximum length plus the 2-byte S7 header. STRING[20] in TIA Portal is 22 bytes.
- A passing Test All checks the configuration only. Submit can still fail if the PLC rejects it, for example when the DB does not exist or the address is out of range on that PLC.
Limits
- Write functions handle one value each. Only reads group several data points into one function.
- TIMER, COUNTER, TIME_OF_DAY and DATE_AND_TIME can be read but not written.
SAP
- SAP returns HTTP 200 even when it rejects an IDoc. The connector reads the response title (IDoc-XML-inbound ok or not ok) and fails the call on not ok.
- A successful send only means SAP received the IDoc. Posting can still fail later with status 51 or 56; configure the ALEAUD return path to see the result in MaestroHub.
- Send units of measure as ISO codes (PCE, KGM), not SAP internal codes (EA, KG), and dates as YYYYMMDD. These are common causes of status 51.
Limits
- S/4HANA Cloud, public edition is not supported, because SAP removed transactional IDocs there. Classic tRFC transport and the SOAP IDoc port are not supported.
- Validation is structural only: no SAP schema, mandatory segment, field length or code list checks. The inbound webhook body is capped at 1 MiB by default.
What teams use it for
Automatic production confirmation
Counts from the line post goods receipts without manual entry.
Order context on the shop floor
SAP orders and materials joined to live machine data.
Material consumption
Actual usage from machines reported back against the order.
Ways to connect Siemens S7 to SAP
In general terms. Check any specific product for its own details.
Compare a custom script, a flow tool, a cloud vendor's edge service and MaestroHub
Swipe sideways to see every column
| A custom script | A flow tool | A cloud vendor's edge service | MaestroHub | |
|---|---|---|---|---|
| Talks Siemens S7 | A library you choose | Community plug-ins | Depends on the vendor | Built in, one of 90+ connectors |
| Names, units and schema | You write it | You build it | Partly, in the vendor's model | One governed namespace |
| Quality on every value | You write it | You build it | Depends on the vendor | Built in, carried through calculations |
| Where each value came from | You write it | You build it | Depends on the vendor | Stamped on every value |
| Survives a network outage | You build it | You build it | Usually, to that vendor's cloud | On disk, per destination, in order |
| Several destinations at once | One script each | Yes, flow by flow | Mostly that vendor's cloud | Any mix, each with its own buffer |
| Permissions and audit | You build it | You build it | Cloud account permissions | Roles, single sign-on, audit trail |
| AI agents can use the data | You build it | You build it | Depends on the vendor | Through the MCP server |
Questions
How do I combine SAP data with PLC data?
Bring PLC values and SAP's IDocs into the same namespace in MaestroHub, so a production count from the line and an order from SAP sit side by side with the same meaning. A pipeline can send a goods movement or production confirmation back into SAP as an IDoc, under permissions and audit.
Do I need to write code to connect Siemens S7 to SAP?
No. You configure the Siemens S7 connection and the SAP output in MaestroHub and join them with a pipeline. Transformations can be added where you need them.
Where does MaestroHub run for this?
On your own infrastructure next to the machines: an edge box, a virtual machine or Kubernetes. Nothing has to leave your network.
Why not just write a script for Siemens S7 to SAP?
A script works on day one. The cost comes later: decoding and naming values, handling bad quality, buffering through outages, keeping credentials safe, and doing it again for the next machine and the next destination. MaestroHub does those once, for every connector.
What else can Siemens S7 data go to?
More than 90 connectors are included in every edition, among them historians, databases, cloud warehouses, message brokers and business systems, so the same values can feed several destinations at once.
Try Siemens S7 to SAP yourself.
The free trial includes every connector. No factory to hand? The Digital Factory Simulator serves OPC UA, Modbus, MQTT and more on your laptop.

