Data Center Lab · Controls, EPMS, BMS and DCIM · Engineering Note

A Common Time Base Does Not Recover Order in Joint-Test Alarm Files

A common time base is necessary for joint-event replay and not sufficient for it, because the delivered alarm matrix stamps annunciation and its own delays span zero to thirty seconds.

K&K drawing V336-E-125: UPS supply, bypass, battery and PDU interface study with BMS monitoring points
K&K program drawing V336-E-125: UPS, bypass and PDU interfaces with monitoring-only BMS points (internal review sheet).

After a feeder trip, two contractors produce two alarm files. Every criterion the joint electrical and cooling test has to answer is a subtraction between those records. The commissioning evidence index makes an unproved time offset a hard gate for that reason, and a failure on a criticality-weight-three object fails that object's whole system gate whatever the average score says. A common clock is necessary for the subtraction. It does not recover order inside either file.

Four differences are named:

  • the interval from disturbance to detection;
  • the time to admit the first load stage;
  • the time for heat-rejection equipment to reach rated capability from a standing start;
  • the ride-through available before loss of cooling becomes a load event.

Against these the index sets one site time source with at least dual-source redundancy. It requires every timestamp to be stored in coordinated universal time and forbids local time and daylight saving inside raw data. It makes the time source and the reference to its offset proof mandatory fields in every evidence package. The tolerance on that offset it leaves to the record engineer, and the source type and hierarchy to the record engineer or the owner.

Every Joint-Test Criterion Is a Subtraction Between Two Files

The controls basis treats protection, sequence-of-events capture and trend as three different performance requirements that cannot substitute for one another. Electrical sequence-of-events stamps must be taken at the device. A gateway or supervisory stamp may not be labelled high-resolution sequence-of-events, or network and polling jitter are counted as the interval between events. Loss of the time source may degrade data quality and may not change any control behaviour. The same basis records that the named failure branches are all "A before or after B"; without sequence-of-events they are unjudgeable after the fact, and an integrated test cannot return a pass or a fail.

The index's time-synchronisation conclusion is the same requirement seen from the test side. If the generator controller, the power-monitoring system, the building-management system, the uninterruptible supply, the high-speed recorder and the cooling-side temperature log each keep their own time base, the four differences cannot be computed.

The Alarm Matrix Omits Time Source, Stamp Quality, and Field Time

The delivered alarm matrix carries 233 rows across 14 columns [TARGET]. Each row states a condition, a priority, a delay, a deadband, a latch rule, an acknowledgement rule, a routing destination, a retention period and its own hold identifier. A time source, a timestamp quality flag and a field time for the condition that raised the row are the three fields none of the fourteen provides. Routing splits the file across six integrators, 87 rows to the power-monitoring integrator and 85 to the building-management integrator [TARGET], so a joint event is reconstructed by construction from two sets of records produced by two contractors.

The File Stamps Annunciation, Not Occurrence

The delay column is a second ordering problem, and it does not depend on the clock at all. 163 of the 233 rows annunciate only after a 30 s persistence, 43 after 5 s, 8 after 2 s and 18 immediately [TARGET]. Those 18 are exactly the life-safety rows, and they are the only rows latched for manual reset and the only rows retained for seven years [TARGET], so the conditions most likely to open a joint event are also the ones that reach the log first. Two conditions occurring in one physical order can therefore arrive in the log in the opposite order, with an inversion of up to 30 s [MODELED, taken here as the span between the longest and shortest delay in the delivered file]. A perfect common clock recovers none of that, because what the file stamps is annunciation and not occurrence. A source-timestamp column carrying the field time of the originating condition would retire the defect outright and return the whole problem to clock offset alone.

That bound belongs to this file and not to the discipline. The delays are deliberate and the deadband column gives the reason for most of them, 131 rows using a 30 s state-persistence band to stop advisory conditions chattering [TARGET]. Retention is set per row at two, five and seven years [TARGET]. Suppression is the one column that does not vary at all: every row may be suppressed in maintenance mode only and only with an audit trail [TARGET]. Every row is marked as requiring review and carries a hold against the record engineer or a supplier. The file was never asked to separate the moment a condition existed from the moment it was declared, and separating them is a schema change rather than a setting.

An Unproved Offset Fails the Joint-Test System Gate

Commissioning already owns the consequence. The time-synchronisation gate reaches every joint scenario and every transient test, and the rule that a criticality-weight-three object carries the system verdict means a single unproved offset withdraws a system result that is otherwise complete. The index also asks which supply feeds the time source itself, so that the source does not fail in the same minute as the events it is stamping, and registers that as an open item against the staged-loading group carrying the rectifier input. No answer to it exists in either document.

Limits and open items

Confirmed: time synchronisation is a precondition of the joint electrical and cooling test, not an information-technology convenience. An unproved offset on a weight-three object fails that object's system gate regardless of the average score. [FACT]

The 233-row, 14-column matrix, the 87 and 85 routing split, the 163 / 43 / 8 / 18 delay counts, the 18 life-safety rows, the 131-row deadband, and the two-, five- and seven-year retention set remain delivered-file counts [TARGET]. The 30 s inversion is the span of those delays [MODELED].

Open: offset tolerance, owed by the record engineer; time-source type and hierarchy; supply class of the time source itself. Sequence-of-events resolution is not published. Nothing here has been sealed. Nothing describes how any installed log behaved. [HOLD]

Stamp the field time

The useful test of the next alarm file is not whether it still shares a clock. It is whether a reviewer can point at one cell that holds the field time of the originating condition. If that cell is still missing, a common clock has not recovered order.


© 2026 K&K Data Service Inc. All rights reserved. Reproduction or republication is permitted only with clear attribution to K&K Data Service Inc. and a working hyperlink to the canonical URL of this article. Excerpts must preserve the technical context, maturity labels, assumptions, and limitations. No excerpt may imply project approval, field validation, certification, or endorsement that the original article does not state.

Source: K&K Data Service Inc., “A Common Time Base Does Not Recover Order in Joint-Test Alarm Files,” https://www.kkdatasvc.com/lab/controls-epms-bms-and-dcim/a-common-clock-does-not-recover-order-in-the-alarm-file/.

Discuss This Constraint. If your project record shows a different result, or the same failure domain under another name, we want to see it. Email inquiry@kkdatasvc.com or use the contact page.