OPC-UA isn’t a brand’s protocol. It’s an open standard, published and maintained by the OPC Foundation, and a growing share of newer CNCs, robots, and packaging equipment ship a server for it out of the box. A laser cutter, a press brake, a robot cell, a newer machine tool, if it has an OPC-UA server running, the setup below applies whether the nameplate says Bystronic, Beckhoff, or something with no dedicated guide in this series at all. The trade for that flexibility is that OPC-UA doesn’t hand you a fixed list of addresses the way a FOCAS parameter number does. You browse for them.
Before you start You’ll need the server’s endpoint URL (
opc.tcp://host:port), whichever security setting it’s running, a username and password if the server requires one, an Ethernet drop, a fixed IP, and the Spall gateway on the same network. Spall connects as a client. It reads. It never writes to the machine.
1. What varies between an OPC-UA server and a register map
A Modbus device or an S7 PLC has a fixed table you fill in from a manual. An OPC-UA server publishes its own tree of nodes, and that tree is different for every device, sometimes for every firmware revision of the same device. The upside is real: node names are usually readable on sight, MachineState, PartCount, SpindleLoad, instead of a bare register number. The cost is that there’s no manual page to copy from. You connect, you look, and you pick.
2. Security modes, and what Spall supports today
An OPC-UA server can be configured to run with no security at all, or with a signed and encrypted session backed by X.509 certificates. Real installs run the whole range: a lot of shop-floor equipment ships with security off by default, and some IT-managed servers require Sign or Sign & Encrypt with a trusted certificate before anything can connect.
Spall connects over an open OPC-UA session today, with an optional username and password if the server requires one. Certificate-based security policies (Sign, Sign & Encrypt) aren’t supported yet. If the server you’re connecting to is set to one of those, either switch it to an unsecured or None policy for the Spall connection, or talk to us before your pilot so we can tell you whether it’s ready.
3. Browse the node tree before you configure anything
This is the step that replaces “read the manual.” Point any OPC-UA client at the endpoint, a free one like UaExpert works fine for a first look, and walk the tree the server publishes. You’re looking for the handful of nodes that carry what you want: a run or execution state, a part or job count, an alarm or condition node, maybe a spindle load or a setpoint. Write down the exact node id for each one you find. They usually look like ns=2;s=Line1.PartCount or i=1001, and note which ones update live by watching the value change while the machine runs a cycle.
Spall’s own Connect a Machine wizard can do this same walk for you. Its Discover tags step opens a short, throwaway session against the server and lists what it finds, so you don’t strictly need a separate client installed. Either way, this is the one step in an OPC-UA setup that has no shortcut. A register map guide can tell you the address in advance. This one can’t, because the server decides its own tree.
What to read first, on a machine you’ve never connected before. Skip the folders full of diagnostic and configuration nodes at the start, most of a real tree is housekeeping you’ll never map. Go straight for whatever carries run or execution state and whatever carries a part or job count. Those two nodes alone are what availability, downtime, and target-vs-actual are built on, worth finding before anything else. An alarm or condition node is next if one exists. Everything past those three is worth adding later, once the basics are flowing and proven against a real cycle.
4. Confirm the endpoint answers
OPC-UA servers commonly listen on port 4840, though plenty of vendors pick their own. Confirm the actual port from the server’s own settings screen rather than assuming. From a PC on the same network:
nc -vz 192.168.1.60 4840
-> Connection to 192.168.1.60 4840 succeeded!
A refused connection here means the server isn’t running, the port is wrong, or a firewall sits between the gateway and the machine. Not a Spall problem yet. This test doesn’t touch Spall.
5. Add the source in Spall
In Spall, add the machine, choose OPC-UA as the source, and enter the endpoint:
opc.tcp://192.168.1.60:4840
Leave the security policy at None unless step 2 told you otherwise, and fill in a username and password only if the server requires one. Assign the Spall gateway and save.
6. Add a tag per node
For every node id from step 3, add a tag with that exact node id as the address. Spall reads whatever value type the server reports for it, no separate data-type field to guess at the way a raw register needs one. As with the Modbus TCP guide’s Signal inbox, every new tag from an OPC-UA source lands there unclassified until someone confirms what it means. Then it feeds availability, downtime, production, and OEE the same as any other connection method.
What Spall does with this data
Availability. A tag mapped to a run or execution-state node splits every hour into running, idle, and down.
Downtime and reasons. Each stop is caught the instant the mapped state node changes. Operators tag the reason, ranked into a Pareto the same as every other protocol in this series.
Production. A tag mapped to a part or job count node drives target-vs-actual by shift and job.
Quality and OEE. Availability, performance, and quality roll into one OEE view, dollar-ranked, whatever protocol fed the underlying tag.
One thing worth repeating Spall opens a read session against the server’s endpoint and nothing else. It never writes a value, a setpoint, or a command back to the machine. Worst case if it can’t reach the server is a gap in the chart. The machine keeps running exactly as it would with no OPC-UA client connected at all.
Quick recap
- OPC-UA is an open standard, not a brand’s protocol, so this guide covers any server that speaks it
- Spall connects over an open session today, with optional username and password. Certificate-based Sign or Sign & Encrypt policies aren’t supported yet
- Browse the node tree first, with a client like UaExpert or Spall’s own Discover tags step, since there’s no manual page to copy an address from
- Confirm port 4840 (or whatever the server’s own settings show) answers before touching Spall’s side
- Add the endpoint, then a tag per node id, exact and case sensitive
- Every new tag lands in the Signal inbox unclassified until someone tells Spall what it means
If a server’s security is locked down tighter than an open session, bring the exact policy name to a pilot call before assuming it won’t work. We’ll tell you plainly what’s ready today and what isn’t.