A Modbus device does not expose variables, objects or tag names. It exposes four flat tables of numbered locations, and every read or write refers to a position in one of them. Everything else — names, units, data types — lives in the device's documentation, not in the protocol.
The four tables
| Table | Width | Access | Function codes |
|---|---|---|---|
| Coil | 1 bit | Read / write | FC01 read, FC05/FC15 write |
| Discrete input | 1 bit | Read only | FC02 |
| Input register | 16 bits | Read only | FC04 |
| Holding register | 16 bits | Read / write | FC03 read, FC06/FC16 write |
The tables are independent. Holding register 100 and input register 100 have nothing to do with one another, and a device may implement one table and not another. There is no way to ask a device which addresses exist: a read either answers or returns an exception.
A register is 16 bits, and that is rarely enough
A single register holds an unsigned 16-bit value: 0 to 65,535. Real measurements do not fit that. A device reporting energy in watt-hours, or a temperature with one decimal place and a sign, has to use more than one register or agree a scaling factor with you.
Two conventions cover most devices:
- Scaling — the register holds 2305 and the manual says the unit is 0.1 V, so the value is 230.5 V. The protocol carries the integer; the meaning is in the documentation.
- Multi-register values — a 32-bit float or integer occupies two consecutive registers, a 64-bit value four. The device decides which register holds the high half, and vendors disagree.
Bits inside a register
Status words often pack several booleans into one holding register, one per bit. The protocol has no concept of this; you read the register as a 16-bit value and mask the bit you want. A tool that lets you address a bit within a register saves you doing that arithmetic in the application.
What this means when you integrate a device
- Find which table the value lives in — it decides the function code.
- Find the address, and check whether the manual is quoting a protocol address or a 4xxxx-style reference.
- Find the width and the data type: one register or two, signed or unsigned, integer or float.
- Find the word order for anything wider than one register.
- Find the scaling factor and the engineering unit.
Those five facts are what a tag definition is. Everything a gateway or SCADA system does with the value depends on getting them right.
Modbus Scanner
Connect to a device and understand its register map.