A flare that's pushing liquid instead of vapor is one of the most visible safety failures a refinery can have, and it almost never happens because the flare tip failed — it happens because the knockout drum upstream of it didn't do its job. Burning rain, flame-out, and heavy smoke are the public symptoms of a problem that starts with level alarms set too late, pump-out capacity that can't keep pace with an upset, or a relief header that lets liquid pool instead of draining back to the drum. For Process Safety Engineers, Flare System Owners, and Operations leads, getting knockout drum overfill prevention right is a core line of defense, not a secondary concern. iFactory's AI-driven platform brings live level trending, pump-out performance, and relief event correlation into one view so liquid carryover risk is visible long before it becomes an incident. Book a Demo to see your flare KOD instrumentation in one dashboard.
Why Liquid Carryover to the Flare Is a Major Incident
A flare is built to handle vapor. When liquid droplets reach the tip, the result is incomplete combustion, smoke, flame instability, and in the worst case a visible spray of burning hydrocarbons falling back toward grade. Design guidance typically targets droplets in the 300 to 600 micron range for separation, since droplets below roughly 300 microns tend to burn off cleanly while larger droplets risk falling out as flaming liquid. The knockout drum exists specifically to strip these droplets out of the relief stream before it ever reaches the stack, which is why its sizing, instrumentation, and pump-out logic carry as much safety weight as the relief valves feeding it.
300–600 Micron Sizing
KOD vapor velocity is set so droplets in this range settle out by gravity before reaching the flare header.
20–30 Minute Retention
Liquid holdup capacity is sized to the largest single relief contingency, giving operators a real intervention window.
LAH, LAHH & Trip Logic
Staged alarms give operators a pre-alarm window, then a hard stop before liquid reaches the carryover point.
Continuous Drainage Design
Relief headers slope continuously back to the drum so condensate and liquid drain in rather than pooling in dead legs.
Setting Level Alarms That Actually Give Operators Time
The gap between a high-level alarm and a high-high trip is the operator's entire window to identify the liquid source and intervene before automatic action kicks in. That gap needs to reflect realistic response time, generally cited in the range of 10 to 30 minutes from first notification to corrective action, not an arbitrary instrument setpoint. Book a Demo to see how that response window is tracked in practice. Below is the typical alarm sequence used to stage operator response ahead of an automatic shutdown.
| Alarm Stage | Trigger Condition | Expected Response |
|---|---|---|
| LAH (High Alarm) | Level rises above normal operating band | Operator investigates liquid source and confirms pump-out is running |
| LAHH (High-High Alarm) | Level continues rising despite LAH response | Operator escalates; isolates upstream source if identified |
| Automatic Pump-Out Start | Level reaches pump-out start setpoint | Pump engages automatically to draw level back down |
| SIF / High-Level Trip | Level approaches carryover risk despite prior stages | Automatic shutdown of relieving source per API RP 14C logic |
Pump-Out Capacity: The Step Most Plants Underestimate
Sizing the drum correctly means nothing if the pump-out system can't draw liquid down faster than it's accumulating. Book a Demo to walk through your pump-out sequencing. Verification needs to cover four things every time a new relief scenario is added to the plant: confirming the largest credible liquid inflow against pump-out rate, confirming pump start reliability at the correct level setpoint, confirming destination capacity at slops or storage, and confirming that high-level alarms account for the time it actually takes the pump to start and ramp.
Worst-Case Inflow Identified
The largest credible liquid surge into the KOD is established as the basis for holdup and pump-out sizing.
Pump-Out Rate Verified
Pump capacity is checked against the worst-case inflow rate to confirm net level reduction, not just gross flow.
Start Reliability Confirmed
Automatic start logic at the correct setpoint is tested, since a pump that starts late erodes the entire holdup margin.
Destination Capacity Checked
Slops or storage receiving the pumped liquid must have available capacity, or the pump-out simply relocates the problem.
Where Overfill Risk Actually Originates
Liquid overfill events generally trace back to one of two root categories: liquid entering from upstream process equipment during a relief, vent, or blowdown event, or liquid quietly accumulating in low points, dead legs, and sub-headers long before any single relief event occurs. Both deserve equal attention in an overfill prevention program.
Every flare liquid carryover event I've reviewed had warning signs in the level trend long before the high-high alarm activated. The instrumentation was usually fine — what was missing was someone watching the trend closely enough, early enough, to act on the slow creep instead of the final alarm.
— Process Safety Engineer, Flare and Relief Systems
Bringing Flare KOD Monitoring Into One System
Most flare overfill prevention programs already have the right instrumentation in place — level transmitters, pump status, and relief valve sequencing all exist somewhere in the control system. What's usually missing is a single view that correlates them, so a slow level creep on the KOD gets flagged against a relief event happening elsewhere in the unit before the two compound into an overfill. iFactory's platform pulls level trending, pump-out performance, and relief activity together so process safety and operations teams can catch the early warning pattern rather than reacting to the LAHH alarm alone. Book a Demo to see your flare system's safeguards unified on one dashboard.
Frequently Asked Questions
What droplet size do flare knockout drums target?
Design guidance typically targets separating droplets in the 300 to 600 micron range before they reach the flare tip.
How much liquid holdup time does a KOD need?
Industry practice generally calls for 20 to 30 minutes of holdup based on the largest single relief contingency.
What causes most flare liquid carryover events?
Carryover usually traces back to upstream relief liquid ingress or liquid pooling in poorly sloped header sections.
Why does pump-out capacity matter if the drum is sized correctly?
A correctly sized drum still overfills if the pump can't draw level down faster than liquid is accumulating during an upset.
How does iFactory support flare KOD overfill prevention?
iFactory unifies level trends, pump-out status, and relief events in real time, surfacing early warning patterns before alarms trip.







