Wire the meter's D1 / D0 / 0 V terminals to a CB 1241 (RS485) on the S7-1200, set both ends to the same line settings, and give the meter a unique slave address. Call MB_COMM_LOAD once, then read blocks of holding registers with MB_MASTER. The one arithmetic step that catches everyone: a meter register printed as 3054 becomes DATA_ADDR 43054. Each measurement is a 32-bit float across two registers, so read into an Array of Word and convert.
- Meter register 3054 → DATA_ADDR 43054, not 3054 and not 3053.
- Every measurement is two registers; energy counters are often four.
- Read blocks, not single values — one request for twelve registers beats six requests.
- Prove the word order against a voltage you can measure before trusting anything else.
Try It: Live Meter HMI Simulator
Before the wiring and the register arithmetic, here is what you are building towards. Move the load, and watch the same values a PLC would read — with the raw holding registers beside them. The three pills at the top are the polling chain: one block read at a time.
PANEL 1 · POWERLOGIC METER · SLAVE 1
Modbus RTU · 19200 8E1 · simulated
WHAT THE PLC ACTUALLY READS
Each value is two holding registers. Register 3054 is DATA_ADDR 43054 in MB_MASTER.
Meter online. The three step pills show the polling chain — one block read at a time, exactly as in the ladder below.
Two buttons reproduce faults you will meet on site. Swap word order leaves the registers untouched but decodes them the wrong way round, which is where readings like 1.7E+34 come from. Phase B open drops one current to zero while the others keep running — obvious on an HMI, invisible in a monthly kWh total.
Hardware and Wiring
Schneider labels the RS-485 pair D1 and D0: D1 is the A line, D0 is the B line. Carry the 0 V reference along with them — an RS-485 link without a common reference works on the bench and fails in a plant.
| Item | Used here | Notes |
|---|---|---|
| CPU | S7-1215C DC/DC/DC | Any S7-1200 or S7-1500 with a serial interface works the same way |
| Serial interface | CB 1241 (RS485) | Or a CM 1241 (RS485) module — only the hardware identifier changes |
| Meter | Schneider PowerLogic energy meter with Modbus RTU | PM5000 series here; EM6400 series uses a different register range |
| Cable | Shielded twisted pair plus a core for 0 V | Daisy chain, terminated at both ends |
| Documentation | The meter's Modbus register list | Non-negotiable — register numbers differ by model and firmware |
Meter Communication Settings
Set these in the meter's own communications menu, then write them down — you will need the same values in MB_COMM_LOAD.
| Meter setting | Value here | Must match |
|---|---|---|
| Protocol | Modbus RTU | The PLC side |
| Address | 1 | Unique on the line, 1 – 247 |
| Baud rate | 19200 | MB_COMM_LOAD |
| Parity | Even | MB_COMM_LOAD |
| Data bits | 8 | Fixed by Modbus RTU |
| Stop bits | 1 with parity | Follows the parity setting |
| Termination | ON if the meter is the last device | The far end of the line |
Register Numbers and DATA_ADDR
This is the step that sends most people back to the manual. Schneider documents register numbers starting at 1; Modbus puts offsets starting at 0 on the wire; and the Siemens instruction wants the 4xxxx holding-register form. Add 40000 to the number in the manual and the instruction does the rest.
| In the meter manual | Modbus offset on the wire | Siemens DATA_ADDR | Function code |
|---|---|---|---|
| Register 3000 | 2999 | 43000 | FC 03 |
| Register 3028 | 3027 | 43028 | FC 03 |
| Register 3054 | 3053 | 43054 | FC 03 |
| Register 3110 | 3109 | 43110 | FC 03 |
| Register 3204 | 3203 | 43204 | FC 03 |
What to Read and in What Blocks
The measurements sit in continuous ranges, so read them in blocks. Three reads cover everything an HMI normally shows, and the energy counter gets its own slow job.
| Quantity | Register | Registers used | Format | Unit |
|---|---|---|---|---|
| Current, phase A | 3000 | 2 | 32-bit float | A |
| Current, phase B | 3002 | 2 | 32-bit float | A |
| Current, phase C | 3004 | 2 | 32-bit float | A |
| Current average | 3010 | 2 | 32-bit float | A |
| Voltage A-B | 3020 | 2 | 32-bit float | V |
| Voltage A-N | 3028 | 2 | 32-bit float | V |
| Voltage L-N average | 3036 | 2 | 32-bit float | V |
| Active power total | 3054 | 2 | 32-bit float | kW |
| Reactive power total | 3062 | 2 | 32-bit float | kVAR |
| Apparent power total | 3070 | 2 | 32-bit float | kVA |
| Power factor total | 3084 | 2 | 32-bit float | — |
| Frequency | 3110 | 2 | 32-bit float | Hz |
| Active energy delivered | 3204 | 4 | 64-bit integer | Wh |
Check your model: the register numbers above follow the PowerLogic PM5000 series. The EM6400 series and older meters use a different range, so confirm every address in the Modbus register list for your exact model and firmware before writing the program.
| Job | Registers read | DATA_ADDR | DATA_LEN | Target array | What it brings back |
|---|---|---|---|---|---|
| Step[1] | 3000 – 3011 | 43000 | 12 | "DB_Meter".RawI | Three phase currents and the average |
| Step[2] | 3028 – 3047 | 43028 | 20 | "DB_Meter".RawU | Phase and line voltages |
| Step[3] | 3054 – 3077 | 43054 | 24 | "DB_Meter".RawP | Active, reactive and apparent power |
| Slow job | 3204 – 3207 | 43204 | 4 | "DB_Meter".RawE | Energy counter — once a minute is enough |
32-Bit Floats and Word Order
Each measurement spans two registers and arrives as an IEEE 754 float. Modbus defines the order of the registers but not how a vendor splits a 32-bit value across them, so the word order has to be confirmed once per meter.
| Step | What to do in TIA Portal |
|---|---|
| 1 | Read the block into an Array of Word in a standard (non-optimised) DB |
| 2 | Give the same memory a second view — an AT overlay declared as Array of DWord, or a matching Array of Real |
| 3 | If the meter sends the high word first, the DWord is already in S7 order — convert it straight to REAL |
| 4 | If the value is absurd, swap the two words (SWAP instruction or a MOVE pair) before converting |
| 5 | Check one value you can measure — line voltage — before trusting the rest |
The Ladder Program
One bit per job in an array, "Meter".Step[1..3]. The bit enables its MB_MASTER network and drives its REQ; the hand-over rung sets the next bit and resets its own as soon as DONE or ERROR appears. Only one request is ever on the line.
| Tag | Data type | Purpose |
|---|---|---|
"Meter".Step | Array[1..3] of Bool | One bit per job; exactly one is TRUE |
"Meter".Done / .Error | Array[1..3] of Bool | Result bits of each job |
"Meter".Status | Array[1..3] of Word | STATUS of each job, kept for diagnostics |
"DB_Meter".RawI | Array[0..11] of Word | Raw current block |
"DB_Meter".RawU | Array[0..19] of Word | Raw voltage block |
"DB_Meter".RawP | Array[0..23] of Word | Raw power block |
"DB_Meter".Current_A … | Real | The converted engineering values |
If the meter stops answering, ERROR arrives after RESP_TO and the chain still advances — one dead device slows the cycle but never freezes it, and Status[n] keeps the reason.
Converting the Raw Registers
With the block in a standard DB and a DWord view over the same memory, the conversion is a single instruction per value.
The same pattern gives voltage, power factor and frequency. The energy counter is the exception: read four registers and assemble the 64-bit value in two halves.
From the PLC to Reports
Energy data is usually wanted per shift, per line or per machine, which means it ends up in a database rather than on a screen.
For the reporting end of that chain see SQL reporting for plant data. For the drive side of the same RS-485 line see Siemens PLC to G120 over Modbus RTU, and for the protocol itself Modbus RTU vs Modbus TCP.
Commission a meter link in the lab
Wire a PowerLogic meter to an S7-1200, read the blocks and prove the scaling against a clamp meter. Pune classroom or live online.
Common Faults
| Symptom | Likely cause | Fix |
|---|---|---|
| No response at all | Address, baud or parity mismatch; D1/D0 swapped | Match the meter's comms menu to MB_COMM_LOAD; swap D1 and D0 once as a test |
| Everything is one register out | Register number used as the offset | Use the 4xxxx form: register 3054 is DATA_ADDR 43054 |
| Values like 1.7E+34 or 3.2E-41 | 32-bit word order reversed | Swap the two registers before converting to REAL |
| Power is right, energy is nonsense | Energy counter is 64-bit, read as 32-bit | Read four registers and build the value in two halves |
| Readings freeze at the last value | Job errors, chain stalled on a held REQ | Let ERROR advance the chain exactly like DONE |
| Exception code 02 | Register does not exist on this model | Check the register list for your exact model and firmware |
| Current reads on one phase only | Wrong CT wiring or the meter is in single-phase mode | Check the meter configuration before blaming Modbus |
Step-by-Step Lab: First Reading from a Schneider Meter
Hands-on- An S7-1215C with a CB 1241 (RS485), a Schneider PowerLogic meter on a live three-phase supply, and its Modbus register list.
- A clamp meter or a multimeter to check one reading against reality.
- Estimated time: 75 minutes.
Wire and terminate
Connect D1, D0 and 0 V to the CB 1241. Jumper TA–T/RA and TB–T/RB, and switch the meter terminator on.
Set the meter
Address 1, 19200 baud, even parity, Modbus RTU.
Load the port
Call MB_COMM_LOAD once from the start-up OB with the same settings.
Read one voltage
Add a single MB_MASTER job: DATA_ADDR 43028, DATA_LEN 2, into two words.
Convert and verify
Build the DWord, convert to REAL and compare with a measured line voltage.
Read in blocks
Replace the single read with the three block jobs and their hand-over rungs.
Add the energy counter
Add a slow fourth job on the energy registers, triggered once a minute.
You can commission a meter link if one measured value matches a clamp meter, the block reads update continuously, and you can explain why register 3054 became DATA_ADDR 43054.
Frequently asked questions
Which Schneider meters can a Siemens PLC read over Modbus RTU?
Any PowerLogic meter with an RS-485 Modbus RTU port — the PM2000, PM5000 and PM8000 families, and the EM6400 series. The PLC side is identical; only the register list changes, so the meter's own Modbus documentation is the one thing you cannot work without.
What DATA_ADDR do I use for register 3054?
43054. The Siemens instruction uses the 4xxxx holding-register form, so add 40000 to the register number printed in the meter manual. The instruction subtracts one internally and puts offset 3053 on the wire.
Why do my voltage readings look like 1.7E+34?
The two registers of the 32-bit float are the wrong way round. Swap them before converting to REAL. Test against a value you can measure — a line voltage of about 415 V is unmistakable when it is right.
How often should I poll an energy meter?
Currents, voltages and power every second or two is plenty for an HMI. Energy counters change slowly, so a separate slow job once a minute keeps the cycle short and the bus quiet.
Can the meter share a line with a drive?
Yes, if both use the same baud rate and parity and have different slave addresses. Add their jobs to the same step chain. Remember that one line means one set of line settings for every device on it.
Do I need a separate gateway for Modbus TCP?
Only if the meter has no Ethernet port and you want it on the plant network. Many PowerLogic meters offer Modbus TCP directly, in which case the PLC uses MB_CLIENT instead of MB_MASTER and the register numbers stay exactly the same.
How do I get the readings into a report?
Either the PLC logs to SQL through the reporting system, or the reporting system polls the meter itself. Pick one. Logging the same counter in two places is the usual reason two reports disagree at the end of a shift.