Skip to main content
Siemens · Technical Blog

Reading a Schneider Energy Meter from a Siemens PLC over Modbus RTU

Wiring, register numbering, 32-bit floats and a ladder step chain — everything between a PowerLogic meter and a usable kW value in the PLC.

2,500+ engineers trained 4.9/5 Google rating 21+ years, Chinchwad, Pune Next batch: contact for dates
Quick answer

Wire the meter's D1 / D0 / 0 V terminals to a CB 1241 (RS485) on the S7-1200, set both ends to the same line settings, and give the meter a unique slave address. Call MB_COMM_LOAD once, then read blocks of holding registers with MB_MASTER. The one arithmetic step that catches everyone: a meter register printed as 3054 becomes DATA_ADDR 43054. Each measurement is a 32-bit float across two registers, so read into an Array of Word and convert.

  • Meter register 3054 → DATA_ADDR 43054, not 3054 and not 3053.
  • Every measurement is two registers; energy counters are often four.
  • Read blocks, not single values — one request for twelve registers beats six requests.
  • Prove the word order against a voltage you can measure before trusting anything else.

Try It: Live Meter HMI Simulator

Before the wiring and the register arithmetic, here is what you are building towards. Move the load, and watch the same values a PLC would read — with the raw holding registers beside them. The three pills at the top are the polling chain: one block read at a time.

PANEL 1 · POWERLOGIC METER · SLAVE 1

Modbus RTU · 19200 8E1 · simulated

POLL Step 1 · 43000 Step 2 · 43028 Step 3 · 43054
V L-N A0V
V L-N B0V
V L-N C0V
CURRENT A0A
CURRENT B0A
CURRENT C0A
ACTIVE kW0kW
POWER FACTOR0
FREQUENCY0Hz
ACTIVE ENERGY DELIVERED0kWh

WHAT THE PLC ACTUALLY READS

Each value is two holding registers. Register 3054 is DATA_ADDR 43054 in MB_MASTER.

Meter online. The three step pills show the polling chain — one block read at a time, exactly as in the ladder below.

Two buttons reproduce faults you will meet on site. Swap word order leaves the registers untouched but decodes them the wrong way round, which is where readings like 1.7E+34 come from. Phase B open drops one current to zero while the others keep running — obvious on an HMI, invisible in a monthly kWh total.

Hardware and Wiring

Schneider labels the RS-485 pair D1 and D0: D1 is the A line, D0 is the B line. Carry the 0 V reference along with them — an RS-485 link without a common reference works on the bench and fails in a plant.

Two-wire RS-485 from the PLC to the meterS7-1215CModbus masterCB 1241 (RS485)communication board slotT/RA · T/RB · Mjumper TA–T/RA and TB–T/RB hereSchneider energy meterSlave address 1 · Modbus RTU19200 baud · even parity · 8 data bitsterminator ON — last device on the lineD1 / A (+)D0 / B (−)0 V commonBIAS + TERMTERMSchneider labels the pair D1/D0 — D1 is A, D0 is B
One master, one meter. Bias and termination at the CB 1241 end, terminator on at the meter.
ItemUsed hereNotes
CPUS7-1215C DC/DC/DCAny S7-1200 or S7-1500 with a serial interface works the same way
Serial interfaceCB 1241 (RS485)Or a CM 1241 (RS485) module — only the hardware identifier changes
MeterSchneider PowerLogic energy meter with Modbus RTUPM5000 series here; EM6400 series uses a different register range
CableShielded twisted pair plus a core for 0 VDaisy chain, terminated at both ends
DocumentationThe meter's Modbus register listNon-negotiable — register numbers differ by model and firmware

Meter Communication Settings

Set these in the meter's own communications menu, then write them down — you will need the same values in MB_COMM_LOAD.

Meter settingValue hereMust match
ProtocolModbus RTUThe PLC side
Address1Unique on the line, 1 – 247
Baud rate19200MB_COMM_LOAD
ParityEvenMB_COMM_LOAD
Data bits8Fixed by Modbus RTU
Stop bits1 with parityFollows the parity setting
TerminationON if the meter is the last deviceThe far end of the line

Register Numbers and DATA_ADDR

This is the step that sends most people back to the manual. Schneider documents register numbers starting at 1; Modbus puts offsets starting at 0 on the wire; and the Siemens instruction wants the 4xxxx holding-register form. Add 40000 to the number in the manual and the instruction does the rest.

From the meter manual to DATA_ADDR — the step everyone gets wrongMeter manualRegister 3054Active power totalOn the wireOffset 3053FC 03 requestMB_MASTERDATA_ADDR := 43054PLCTwo registers → REALSchneider lists register numbers that start at 1. Modbus puts offsets that start at 0 on the wire.The Siemens instruction takes the 4xxxx form, so add 40000 to the register number: 3054 becomes DATA_ADDR 43054.If every value is one register out, this arithmetic is why. Read a known quantity — line voltage — to prove it.
Register 3054 in the manual becomes DATA_ADDR 43054 in MB_MASTER, and offset 3053 on the wire.
In the meter manualModbus offset on the wireSiemens DATA_ADDRFunction code
Register 3000299943000FC 03
Register 3028302743028FC 03
Register 3054305343054FC 03
Register 3110310943110FC 03
Register 3204320343204FC 03
MB_MASTER: MODE plus DATA_ADDR decide the function codeMODEDATA_ADDRFUNCTION CODEMEANING000001 – 09999FC 01Read coils010001 – 19999FC 02Read discrete inputs030001 – 39999FC 04Read input registers040001 – 49999FC 03Read holding registers100001 – 09999FC 05 / 15Write coil(s)140001 – 49999FC 06 / 16Write holding register(s)200001 / 40001 …FC 15 / 16Always multiple writeSiemens uses the documented 4xxxx numbering, so DATA_ADDR 40110 really is register 40110 — the instruction handles the offset.
Read or write is MODE; the register range in DATA_ADDR does the rest.

What to Read and in What Blocks

The measurements sit in continuous ranges, so read them in blocks. Three reads cover everything an HMI normally shows, and the energy counter gets its own slow job.

QuantityRegisterRegisters usedFormatUnit
Current, phase A3000232-bit floatA
Current, phase B3002232-bit floatA
Current, phase C3004232-bit floatA
Current average3010232-bit floatA
Voltage A-B3020232-bit floatV
Voltage A-N3028232-bit floatV
Voltage L-N average3036232-bit floatV
Active power total3054232-bit floatkW
Reactive power total3062232-bit floatkVAR
Apparent power total3070232-bit floatkVA
Power factor total3084232-bit float—
Frequency3110232-bit floatHz
Active energy delivered3204464-bit integerWh
JobRegisters readDATA_ADDRDATA_LENTarget arrayWhat it brings back
Step[1]3000 – 30114300012"DB_Meter".RawIThree phase currents and the average
Step[2]3028 – 30474302820"DB_Meter".RawUPhase and line voltages
Step[3]3054 – 30774305424"DB_Meter".RawPActive, reactive and apparent power
Slow job3204 – 3207432044"DB_Meter".RawEEnergy counter — once a minute is enough
Three reads per cycle, chained by step bitsStep[1]43000, 12 registerscurrents and averageDONE / ERRORStep[2]43028, 20 registersvoltagesDONE / ERRORStep[3]43054, 24 registerspower, PF, frequencyenergy counters need only a slow fourth job — once a minute is plenty
Three fast jobs for the live values, one slow job for the counter.

32-Bit Floats and Word Order

Each measurement spans two registers and arrives as an IEEE 754 float. Modbus defines the order of the registers but not how a vendor splits a 32-bit value across them, so the word order has to be confirmed once per meter.

Two registers, one 32-bit floatRegister 3054high wordRegister 3055low wordDWord32 bits togetherREALe.g. 412.6Schneider PowerLogic meters send the high word first, which matches how an S7 stores a DWord — so the two registerscan usually be overlaid directly with an AT view or moved into a DWord and converted.If a voltage reads as something like 1.7E+34 or 0.00003, the word order is reversed: swap the two registers first.Energy counters are often 64-bit — four registers — and are read the same way, in pairs.
Two registers, combined into a DWord, converted to a REAL.
StepWhat to do in TIA Portal
1Read the block into an Array of Word in a standard (non-optimised) DB
2Give the same memory a second view — an AT overlay declared as Array of DWord, or a matching Array of Real
3If the meter sends the high word first, the DWord is already in S7 order — convert it straight to REAL
4If the value is absurd, swap the two words (SWAP instruction or a MOVE pair) before converting
5Check one value you can measure — line voltage — before trusting the rest

The Ladder Program

One bit per job in an array, "Meter".Step[1..3]. The bit enables its MB_MASTER network and drives its REQ; the hand-over rung sets the next bit and resets its own as soon as DONE or ERROR appears. Only one request is ever on the line.

TagData typePurpose
"Meter".StepArray[1..3] of BoolOne bit per job; exactly one is TRUE
"Meter".Done / .ErrorArray[1..3] of BoolResult bits of each job
"Meter".StatusArray[1..3] of WordSTATUS of each job, kept for diagnostics
"DB_Meter".RawIArray[0..11] of WordRaw current block
"DB_Meter".RawUArray[0..19] of WordRaw voltage block
"DB_Meter".RawPArray[0..23] of WordRaw power block
"DB_Meter".Current_A …RealThe converted engineering values
Network 1: Load the RS-485 port once at start-up
%DB10"MB_COMM_LOAD_DB"MB_COMM_LOAD"MB_COMM_LOAD""FirstScan"ENENOREQTRUEPORT"Local~CB_1241_(RS485)"BAUD19200PARITY2FLOW_CTRL0RTS_ON_DLY0RTS_OFF_DLY0RESP_TO1000MB_DB"MB_MASTER_DB".MB_DBDONE"Meter".PortDoneERROR"Meter".PortErrorSTATUS"Meter".PortStatus
Network 2: First scan — start the chain at step 1
"FirstScan""Meter".Step[1]S
Network 3: Step 1 — read the current block (registers 3000 …)
%DB11"MB_MASTER_DB"MB_MASTER"MB_MASTER""Meter".Step[1]ENENOREQ"Meter".Step[1]MB_ADDR1MODE0DATA_ADDR43000DATA_LEN12DATA_PTR"DB_Meter".RawIDONE"Meter".Done[1]BUSY"Meter".BusyERROR"Meter".Error[1]STATUS"Meter".Status[1]
Network 4: Step 1 done or error → set step 2, reset step 1
"Meter".Done[1]"Meter".Error[1]"Meter".Step[2]S"Meter".Step[1]R
Network 5: Step 2 — read the voltage block (registers 3028 …)
%DB11"MB_MASTER_DB"MB_MASTER"MB_MASTER""Meter".Step[2]ENENOREQ"Meter".Step[2]MB_ADDR1MODE0DATA_ADDR43028DATA_LEN20DATA_PTR"DB_Meter".RawUDONE"Meter".Done[2]BUSY"Meter".BusyERROR"Meter".Error[2]STATUS"Meter".Status[2]
Network 6: Step 2 done or error → set step 3, reset step 2
"Meter".Done[2]"Meter".Error[2]"Meter".Step[3]S"Meter".Step[2]R
Network 7: Step 3 — read power, power factor and frequency (registers 3054 …)
%DB11"MB_MASTER_DB"MB_MASTER"MB_MASTER""Meter".Step[3]ENENOREQ"Meter".Step[3]MB_ADDR1MODE0DATA_ADDR43054DATA_LEN24DATA_PTR"DB_Meter".RawPDONE"Meter".Done[3]BUSY"Meter".BusyERROR"Meter".Error[3]STATUS"Meter".Status[3]
Network 8: Step 3 done or error → set step 1 again, reset step 3 (cycle repeats)
"Meter".Done[3]"Meter".Error[3]"Meter".Step[1]S"Meter".Step[3]R

If the meter stops answering, ERROR arrives after RESP_TO and the chain still advances — one dead device slows the cycle but never freezes it, and Status[n] keeps the reason.

Converting the Raw Registers

With the block in a standard DB and a DWord view over the same memory, the conversion is a single instruction per value.

Network 9: Build the phase-A current as a REAL
CONVDWord to RealINOUT"DB_Meter".RawI_DW[0]"DB_Meter".Current_Aamps
Network 10: Build the total active power as a REAL
CONVDWord to RealINOUT"DB_Meter".RawP_DW[0]"DB_Meter".Power_kWkilowatts

The same pattern gives voltage, power factor and frequency. The energy counter is the exception: read four registers and assemble the 64-bit value in two halves.

From the PLC to Reports

Energy data is usually wanted per shift, per line or per machine, which means it ends up in a database rather than on a screen.

Where the numbers go after the PLCEnergy meterModbus registersS7-1200REAL values in a DBHMI / SCADALive values and trendsSQL / reportkWh per shift, per machineThe PLC is only the middle of the chain. Decide early whether the energy counter is logged from the PLC or readdirectly by the reporting system — logging the same counter twice is the usual cause of mismatched reports.
The PLC is the middle of the chain — decide once who owns the energy counter.

For the reporting end of that chain see SQL reporting for plant data. For the drive side of the same RS-485 line see Siemens PLC to G120 over Modbus RTU, and for the protocol itself Modbus RTU vs Modbus TCP.

Commission a meter link in the lab

Wire a PowerLogic meter to an S7-1200, read the blocks and prove the scaling against a clamp meter. Pune classroom or live online.

Book a Free Demo Class

Common Faults

SymptomLikely causeFix
No response at allAddress, baud or parity mismatch; D1/D0 swappedMatch the meter's comms menu to MB_COMM_LOAD; swap D1 and D0 once as a test
Everything is one register outRegister number used as the offsetUse the 4xxxx form: register 3054 is DATA_ADDR 43054
Values like 1.7E+34 or 3.2E-4132-bit word order reversedSwap the two registers before converting to REAL
Power is right, energy is nonsenseEnergy counter is 64-bit, read as 32-bitRead four registers and build the value in two halves
Readings freeze at the last valueJob errors, chain stalled on a held REQLet ERROR advance the chain exactly like DONE
Exception code 02Register does not exist on this modelCheck the register list for your exact model and firmware
Current reads on one phase onlyWrong CT wiring or the meter is in single-phase modeCheck the meter configuration before blaming Modbus

Step-by-Step Lab: First Reading from a Schneider Meter

Hands-on
Before you start
  • An S7-1215C with a CB 1241 (RS485), a Schneider PowerLogic meter on a live three-phase supply, and its Modbus register list.
  • A clamp meter or a multimeter to check one reading against reality.
  • Estimated time: 75 minutes.
1

Wire and terminate

Connect D1, D0 and 0 V to the CB 1241. Jumper TA–T/RA and TB–T/RB, and switch the meter terminator on.

On screen: the meter communications menu showing address, baud rate and parity.
Continuity on all three cores, shield earthed at one end only.
2

Set the meter

Address 1, 19200 baud, even parity, Modbus RTU.

The meter shows the settings in its comms menu and keeps them after a power cycle.
3

Load the port

Call MB_COMM_LOAD once from the start-up OB with the same settings.

DONE pulses TRUE and STATUS stays at zero.
4

Read one voltage

Add a single MB_MASTER job: DATA_ADDR 43028, DATA_LEN 2, into two words.

Two non-zero words arrive. If STATUS reports an exception, re-check the register number arithmetic.
5

Convert and verify

Build the DWord, convert to REAL and compare with a measured line voltage.

The value lands near 240 V line-to-neutral or 415 V line-to-line. Anything like 1.7E+34 means the word order is reversed.
6

Read in blocks

Replace the single read with the three block jobs and their hand-over rungs.

All three Done bits pulse in turn and the whole measurement set updates every cycle.
7

Add the energy counter

Add a slow fourth job on the energy registers, triggered once a minute.

The counter only ever increases, and the cycle time of the fast jobs does not change.
Checkpoint — how to know you did it right

You can commission a meter link if one measured value matches a clamp meter, the block reads update continuously, and you can explain why register 3054 became DATA_ADDR 43054.

Frequently asked questions

Which Schneider meters can a Siemens PLC read over Modbus RTU?

Any PowerLogic meter with an RS-485 Modbus RTU port — the PM2000, PM5000 and PM8000 families, and the EM6400 series. The PLC side is identical; only the register list changes, so the meter's own Modbus documentation is the one thing you cannot work without.

What DATA_ADDR do I use for register 3054?

43054. The Siemens instruction uses the 4xxxx holding-register form, so add 40000 to the register number printed in the meter manual. The instruction subtracts one internally and puts offset 3053 on the wire.

Why do my voltage readings look like 1.7E+34?

The two registers of the 32-bit float are the wrong way round. Swap them before converting to REAL. Test against a value you can measure — a line voltage of about 415 V is unmistakable when it is right.

How often should I poll an energy meter?

Currents, voltages and power every second or two is plenty for an HMI. Energy counters change slowly, so a separate slow job once a minute keeps the cycle short and the bus quiet.

Can the meter share a line with a drive?

Yes, if both use the same baud rate and parity and have different slave addresses. Add their jobs to the same step chain. Remember that one line means one set of line settings for every device on it.

Do I need a separate gateway for Modbus TCP?

Only if the meter has no Ethernet port and you want it on the plant network. Many PowerLogic meters offer Modbus TCP directly, in which case the PLC uses MB_CLIENT instead of MB_MASTER and the register numbers stay exactly the same.

How do I get the readings into a report?

Either the PLC logs to SQL through the reporting system, or the reporting system polls the meter itself. Pick one. Logging the same counter in two places is the usual reason two reports disagree at the end of a shift.

Reviewed by Bhawesh Kumar Singh Industrial Automation Trainer and Industry 4.0 Consultant · Softwell Automation · 21+ years industry experience

Get the full syllabus + free demo class

Share your details — a Softwell training advisor will call you within 24 hours with batch dates, fees and hardware access options.

No spam. Used only to share course details for this enquiry.

Learn with practical industrial examples

Join live online, Pune classroom or corporate in-plant automation training.

Request Course Details
Verified learning pathway

Discuss Your Automation Requirement

Get guidance for training, corporate programs, projects or technical resources.

Content reviewed: 22 September 2026

☎ Call WhatsApp ✉ Email Enquire Now