# Modbus Analyzer

**URL:** <https://discuss.saleae.com/t/modbus-analyzer/2024>\
**Category:** Logic 2 Software\
**Created:** [January 5, 2023, 6:19pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024 "2023-01-05T18:19:47Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jon.slavic](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@jon.slavic](https://discuss.saleae.com/u/jon.slavic)\
**Post date:** [January 5, 2023, 6:19pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/1 "2023-01-05T18:19:47Z")

</div>

First time using the Modbus Analyzer, looking at my data (01030000000AC5CD sent, 01031433D30007000003870DDE01020000000060000001BD1F returned) in the attached capture. The analyzer is setup at a Modbus RTU master and correctly reads the sent command but incorrectly reads the response.

Is I set the analyzer to slave, it doesn’t decode anything correctly. Any help?  
[Modbus Capture (read holding registers - 10 registers).sal](https://discuss.saleae.com/uploads/short-url/80AsOLIcbDCGTgFMG24xVc4EMLH.sal) (289.3 KB)

---

<div class="post-metadata">

**Author:** ![timreyes](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/timreyes/32/108_2.png) [@timreyes](https://discuss.saleae.com/u/timreyes)\
**Post date:** [January 6, 2023, 8:09pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/2 "2023-01-06T20:09:06Z")

</div>

@jon.slavic I may have gotten the response to decode properly by trimming the capture to only show the response, and using the following Modbus settings.

 ![Screen Shot 2023-01-06 at 3.05.48 PM](https://canada1.discourse-cdn.com/flex030/uploads/saleae/original/2X/0/05dd78c2893e238da1e65a5a140997cfdb8355c1.png)

The checksum seems to be correct as well. I’ll provide the .sal file here.  
[Modbus-Slave-Only.sal](https://discuss.saleae.com/uploads/short-url/35BXcbJl3m9s18wXX8RqgkasbN7.sal) (148.6 KB)

As a first step, can you confirm if the results shown above are you what you expect for the response?

If so, your issue might be related to the GitHub Issue post below, which we’ve recorded for the Modbus analyzer.

> <https://github.com/saleae/modbus-analyzer/issues/2>
>
> Specifically, we should have a combined mode, called "Modbus/RTU - Master & Slav…e", which auto-detects the messages on a single data line as either Master or Slave. Modbus can have both Master & Slave messages on a single line.
> 
> The simplest solution is to try both decodings modes (master and slave) for each decoded frame (single blue decoded box) – the correct one for is the one with a valid Checksum.

---

<div class="post-metadata">

**Author:** ![jon.slavic](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@jon.slavic](https://discuss.saleae.com/u/jon.slavic)\
**Post date:** [January 10, 2023, 12:37pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/3 "2023-01-10T12:37:36Z")

</div>

Thanks Tim, make sense. Your decode is correct. This should be a pretty simple decoder to do master and slave in one transactions with the Modbus protocol.

---

<div class="post-metadata">

**Author:** ![peter](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@peter](https://discuss.saleae.com/u/peter)\
**Post date:** [December 8, 2023, 10:13pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/4 "2023-12-08T22:13:02Z")

</div>

@timreyes Any chance the decoder will get improved? I love the saleae analyzer (still using the logic 16 for years) but I feel the modbus decoder could use some improvements when both master and slave device are on the same 2-wire RS485 bus.

Same issue as jon.slavic where the data is correct, but the analyzer is unable to process the reply.  
Master sent this request: 01 03 50 06 00 02 35 0A  
Slave sent this reply 01 03 04 43 67 E6 66 94 22 (which is correct)

The decoder however is not able to distinguish between the request and answer. The only way to decode this is as you indeed showed by trimming the data so only the reply is shown and switching the decoder from RTU client to RTU server.

 ![image](https://canada1.discourse-cdn.com/flex030/uploads/saleae/original/2X/f/f4b971104b1c3c5c1fd43f2967d5efa99631a808.png)

[RS485 modbus.sal](https://discuss.saleae.com/uploads/short-url/vocI5aptdE8zaa2nTiOklhEd5Ee.sal) (5.2 KB)

---

<div class="post-metadata">

**Author:** ![timreyes](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/timreyes/32/108_2.png) [@timreyes](https://discuss.saleae.com/u/timreyes)\
**Post date:** [December 9, 2023, 2:05am UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/5 "2023-12-09T02:05:58Z")

</div>

@peter Thanks for following up on this. Our software team is currently prioritizing other projects at the moment, and we’re unfortunately unable to work on analyzer improvements for the Modbus analyzer anytime soon because of it.

Having said that, feel free to make use of our Protocol Analyzer SDK to make any changes or improvements to any of our analyzers, including our Modbus analyzer! This will require C++ knowledge.

> **[Protocol Analyzer SDK](https://support.saleae.com/saleae-api-and-sdk/protocol-analyzer-sdk)**

In any case, we apologize for not being able to work on this immediately.

---

<div class="post-metadata">

**Author:** ![drSysManOne](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/drsysmanone/32/2089_2.png) [@drSysManOne](https://discuss.saleae.com/u/drSysManOne)\
**Post date:** [November 18, 2025, 10:35am UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/6 "2025-11-18T10:35:52Z")

</div>

Hello!

Did u resolved the problem ? Any tips & tricks ?

---

<div class="post-metadata">

**Author:** ![timreyes](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/timreyes/32/108_2.png) [@timreyes](https://discuss.saleae.com/u/timreyes)\
**Post date:** [November 19, 2025, 12:45am UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/7 "2025-11-19T00:45:20Z")

</div>

@drSysManOne Thanks for following up on this! We’re currently still tracking this request below (apologies our status on that hasn’t changed yet).

> <https://github.com/saleae/modbus-analyzer/issues/2>
>
> Specifically, we should have a combined mode, called "Modbus/RTU - Master & Slav…e", which auto-detects the messages on a single data line as either Master or Slave. Modbus can have both Master & Slave messages on a single line.
> 
> The simplest solution is to try both decodings modes (master and slave) for each decoded frame (single blue decoded box) – the correct one for is the one with a valid Checksum.

Although we’re still unable to work on analyzer updates right now outside of software breaking bugs, please feel free to check out Binho’s services below!  
[https://binho.io/pages/custom-protocol-analyzer-development](https://binho.io/pages/custom-protocol-analyzer-development)

Their engineers are able to provide services to develop custom low level analyzers and extensions for our software, and they may be a great resource for modifying our Modbus analyzer to suit your exact needs. More information on their services can be found in the link above in case you are interested in reaching out to them!

---

<div class="post-metadata">

**Author:** ![drSysManOne](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/drsysmanone/32/2089_2.png) [@drSysManOne](https://discuss.saleae.com/u/drSysManOne)\
**Post date:** [November 19, 2025, 10:50am UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/8 "2025-11-19T10:50:34Z")

</div>

Hello!

Thanks for the answer. Is there a tutorial: “how to write my own analyzer” ?

---

<div class="post-metadata">

**Author:** ![timreyes](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/timreyes/32/108_2.png) [@timreyes](https://discuss.saleae.com/u/timreyes)\
**Post date:** [November 20, 2025, 6:03pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/9 "2025-11-20T18:03:21Z")

</div>

@drSysManOne We have two useful resources below!

1. [Readme](https://github.com/saleae/SampleAnalyzer/blob/master/readme.md) - This document will walk you through how to modify our template SampleAnalyzer to suit your needs, including steps to rename, setup, build, and debug your analyzer.

2. [Analyzer\_API](https://github.com/saleae/SampleAnalyzer/blob/master/docs/Analyzer_API.md) - This is the documentation for the Saleae C++ Analyzer API.

---

<div class="post-metadata">

**Author:** ![drSysManOne](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.saleae.com/drsysmanone/32/2089_2.png) [@drSysManOne](https://discuss.saleae.com/u/drSysManOne)\
**Post date:** [November 20, 2025, 6:54pm UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/10 "2025-11-20T18:54:36Z")

</div>

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![r.jansen](https://avatars.discourse-cdn.com/v4/letter/r/a87d85/32.png) [@r.jansen](https://discuss.saleae.com/u/r.jansen)\
**Post date:** [September 1, 2026, 10:15am UTC](https://discuss.saleae.com/t/modbus-analyzer/2024/11 "2026-09-01T10:15:55Z")

</div>

There is another, hopefully simpler, issue with the modbus analyzer.

Looking at the printscreen from Peter, the analyzer does not validate the timing.  
According to the Modbus RTU specification

> If a silent interval of more than 1.5 character times occurs between two characters, the message frame is declared incomplete and should be discarded by the receiver.

If we can change the current analyzer to reset the protocol decoding after this timeout, it will restart and decode the response correctly.For me this would be a perfectly acceptable solution.
