How to scan Modbus registers

Finding a device's real register map when the documentation is missing or wrong, without hammering the device or writing to it.

6 min read · Updated

Sometimes the manual is missing, sometimes it describes a different firmware, and sometimes the device was configured by someone who has left. Scanning finds what the device actually answers.

Scan safely

  • Read only. There is never a reason to write during discovery, and a stray write to a live device can change a setpoint.
  • Rate limit. A device serving a control loop should not also be answering hundreds of requests a second. A minimum interval between requests, and a cap per second, keep the scan polite.
  • One request at a time per link. Modbus serial is strictly one outstanding request; treating TCP the same way avoids surprising cheap devices.
  • Get permission. Scanning a production network is an action with consequences; agree it first.

Why block reads beat one-at-a-time

Reading 65,536 addresses individually is tens of thousands of round trips. Reading blocks of 100 is a hundred times fewer. The complication is that one unmapped address makes the whole block fail with exception 02.

The way around this is to treat a failed block as a question rather than an answer:

This finds the boundaries of the real blocks in a few dozen requests instead of thousands. A timeout is treated differently from an exception: an exception means the device is answering and the block can be split, a timeout means the device has stopped talking and splitting will not help.

Identifying what you found

A map of which addresses answer is only half the job. The values themselves suggest their own types:

  • Two consecutive registers that decode to a plausible float — a voltage near 230, a frequency near 50 — are probably a 32-bit float.
  • A register that counts steadily upward is a counter; if it jumps irregularly, the word order is wrong.
  • A register holding a small number that changes between a handful of values is likely an enumeration or a status word.
  • ASCII text is visible as printable characters in the high and low bytes.
The Modbus Scanner suggests data types and byte order from the values, and exports the result as io-tags.json, CSV or Excel so the map becomes a tag definition rather than a screenshot.

Before you scan, try the identity

FC43/14, Read Device Identification, is read-only and often returns the vendor, product code and revision. When a device supports it, you know what you are talking to before scanning a single register — and you may find the right manual.

Free tool

Modbus Scanner

Connect to a device and understand its register map.

How to scan Modbus registers | Modbus Logic