Note
What Niagara does with the Modbus address you type
A Modbus point that reads a completely unrelated register is usually not a wiring fault. The address field holds a format and a string, and the format it starts on is not the one the vendor document is written in.
- Modbus
- Integration
- Station engineering
The field is not a number
The address on a Modbus proxy extension is a small component of its own. It carries two properties: an address format — one of hex, decimal or modbus — and the address itself, stored as a string. Nothing is decided until the driver reads both together.
The format a fresh address starts on is hex. So typing
40001 into a point whose format has not been changed asks for data
address 0x40001, which is 262145. Validation does not stop it either: in hex mode
the only check is that the parsed value is not negative. The point is accepted, the
device answers with an exception or with something else entirely, and the argument
on site is about the device.
What each format does to the number
| Format | Parsed as | Sent as the data address |
|---|---|---|
| hex (default) | base 16 | the value, unchanged |
| decimal | base 10 | the value, unchanged |
| modbus | base 10 | the value with its group prefix removed |
Only the third one does the subtraction that vendor documentation assumes. In modbus format the driver strips the prefix in a fixed order: above 40000 it subtracts 40001, above 30000 it subtracts 30001, above 20000 it subtracts 20001, above 10000 it subtracts 10001, and otherwise it subtracts 1. That is the off-by-one, done for you — but only in that one format.
Hex and decimal both hand the number to the wire as it stands. They are the right choice when a vendor publishes true zero-based data addresses, which some do, and the wrong choice for any document written in the five-digit convention.
The boundary values fall through
Each of those tests is a strict greater-than. So 40000 is not above
40000, drops to the next test, is above 30000, and comes out as data address 9999 —
an input-register offset, from an address that reads like a holding register. The
separate check that decides which register group an address belongs to wants
above 40000 for holding and above 30000 but below 40000 for input, so
40000 belongs to neither group.
The same gap exists at 30000, 20000, 10000 and 0. In the five-digit convention none
of those is a legal address — every group starts at x0001 — so this is
only reachable from a typo or from a generated point list that is one out. It is
worth knowing because nothing reports it. There is no fault and no warning; the
point simply reads a different register.
The 2xxxx range is accepted. In modbus format an address is considered valid anywhere from 0 to 49999, and 20001 upwards is mapped by subtracting 20001. Very few devices publish anything in that range, so an address that lands there is almost always a mistyped 30000-series address that has been quietly accepted.
Nine data types, and the default is unsigned
The data type is a separate decision from the address, and it settles two things at once: how many consecutive registers the point reads, and how the bits are interpreted.
| Data type | Registers | Signed |
|---|---|---|
| Integer (default) | 1 | no |
| Signed integer | 1 | yes |
| Long | 2 | yes |
| Unsigned long | 2 | no |
| Float | 2 | — |
| Unsigned 48-bit long | 3 | no |
| Double | 4 | — |
| Signed 64-bit long | 4 | yes |
| Unsigned 64-bit long | 4 | no |
A point left on the default reads one register, unsigned. A flow or outside-air temperature published as tenths of a degree then reads 65506 at −3.0 °C rather than −30, and the trend looks like a sensor that fails in cold weather. Anything that can go negative needs the signed type chosen explicitly.
The register count also matters for how the point is grouped. A four-register double starting one register before the end of a contiguous block quietly reaches into whatever follows it.
Three byte orders for 32 bits, and one arrangement is missing
For two-register values the driver offers exactly three arrangements —
1032, which is the default, 3210 and 0123.
The fourth possible arrangement, 2301, is not on the list. A device that
publishes its 32-bit values that way cannot be read correctly by setting a property:
the practical answer is to read the two registers as separate 16-bit points and
combine them in logic, or to have the device's own word order changed where its
configuration allows it.
Values of four registers get eight arrangements rather than three, defaulting to
76543210. Meters that publish 64-bit energy totals are the common case,
and the default is the one most of them use.
The order to change things in
When a value is wrong, these are three independent choices and changing them at random turns a five-minute fix into an afternoon. Work through them in order:
- Address format first. It decides what the string you typed even means, and it is a property of each address rather than of the device.
- Then the data type. A value that is plausible but negative-looking, or that is roughly right but jumps to 65535, is a sign or width problem.
- Then the byte order. A value that is nonsense by orders of magnitude, on a point that reads two or four registers, is word order.
The companion note on Modbus register addressing covers the conventions themselves and why a vendor document and a register map disagree, and poll scheduling and busy time covers what happens once the points are right and there are a lot of them. Where a map has to be read properly before any of this, protocol integration is that work, and station engineering is the station around it.
Related
Where this comes up in the work
Protocols & data
Field protocol integration and the data behind it: BACnet, Modbus, M-Bus and MQTT, into a building system, a database or a dashboard.
Station engineering
JACE controller and Niagara station setup end to end: platform commissioning, TLS, users, roles, BACnet and Modbus, tagging, histories, alarms, backups.
More notes
Other things worth writing down
Why a Modbus point reads the wrong register
Modbus decimal addressing is zero-based, vendor documentation is not, and the Address Format property decides which of the two you are typing.
- Modbus
- Integration
- Station engineering
Why a Modbus network sits at 95% busy time
Busy time is the duty cycle of one poll thread per network, not host CPU. What it measures, where the time goes, and what actually brings it down.
- Modbus
- Performance
- Station engineering
Why a BACnet write relinquishes on its own
Fallback is level 17, which is not a BACnet priority. What the driver sends when a point falls to it, and why the in slot sometimes changes nothing.
- BACnet
- Integration
- Station engineering
Next step
Tell us the version, the hardware, and what it has to do.
You will get a written scope and a fixed price against it. If the honest answer is that you do not need us, you will get that instead.