# Modbus sniffer?

**URL:** https://discourse.nodered.org/t/modbus-sniffer/54290
**Category:** General
**Tags:** modbus
**Created:** [25 November 2021 20:50 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290 "2021-11-25T20:50:40Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![TheMiloNet](https://avatars.discourse-cdn.com/v4/letter/t/c68b51/32.png) [@TheMiloNet](https://discourse.nodered.org/u/TheMiloNet)
#### Post date: [25 November 2021 20:50 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/1 "2021-11-25T20:50:40Z")

</div>

hi all, i am trying to implement a modbus sniffer. you will wonder why. very simple. I have a heat pump (slave) that communicates in modbus with its lcd panel (master). I would like to fetch the machine data without adding a second master to the modbus network. I then bought a modbus tcp converter and put it as a client to the tcp listner on nodered. I see a lot of traffic coming. Do I find any projects ready to implement it? Can anyone help me? I would just like to read the answers the machine sends to the panel! thanks a lot

---

<div class="post-metadata">

### Author: ![Folgore](https://avatars.discourse-cdn.com/v4/letter/f/edb3f5/32.png) [@Folgore](https://discourse.nodered.org/u/Folgore)
#### Post date: [27 November 2021 17:00 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/2 "2021-11-27T17:00:25Z")

</div>

Hi, have you bit a tcp/serial converter? If yes...the serial si RS485? If yes...you must link a cable in parallel at the serial. If there Is a terminarono resistant you must put this at last device...(your converter.).

---

<div class="post-metadata">

### Author: ![grant1](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/grant1/32/49890_2.png) [@grant1](https://discourse.nodered.org/u/grant1)
#### Post date: [27 November 2021 20:40 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/3 "2021-11-27T20:40:29Z")

</div>

When you say "I see a lot of traffic coming", are you referring to what you see in the Debug pane?

If you have not done so already, I would recommend you install [these Modbus nodes](https://flows.nodered.org/node/node-red-contrib-modbus) and then connect the modbus-read node and insert some values for Unit-Id (the slave address), Address (e.g. 123), etc. You will probably also have to configure your TCP converter as a server. In my case, I use an [RS485 to USB adapter](https://www.amazon.com/Serial-Converter-Adapter-Supports-Windows/dp/B0195ZD3P4/ref=sr_1_1_sspa?keywords=rs485+to+usb&qid=1638045609&sr=8-1-spons&psc=1&spLa=ZW5jcnlwdGVkUXVhbGlmaWVyPUEyRkw5SFFUOFU3VDNCJmVuY3J5cHRlZElkPUEwMTU5NzEzMkhVUjVYVTRaSVQ4TiZlbmNyeXB0ZWRBZElkPUEwNzQxOTU3M0ZKTFpFVEpDRUZPVCZ3aWRnZXROYW1lPXNwX2F0ZiZhY3Rpb249Y2xpY2tSZWRpcmVjdCZkb05vdExvZ0NsaWNrPXRydWU=).

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/1/c1f4043a810b0b645d67c40f1ae3e40a6ca364ce.png)

---

<div class="post-metadata">

### Author: ![Folgore](https://avatars.discourse-cdn.com/v4/letter/f/edb3f5/32.png) [@Folgore](https://discourse.nodered.org/u/Folgore)
#### Post date: [27 November 2021 21:16 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/4 "2021-11-27T21:16:16Z")

</div>

In modbus serial bus IS not possible have more master. If you sniffing a serial....you need a serial node on node-red.

---

<div class="post-metadata">

### Author: ![TheMiloNet](https://avatars.discourse-cdn.com/v4/letter/t/c68b51/32.png) [@TheMiloNet](https://discourse.nodered.org/u/TheMiloNet)
#### Post date: [27 November 2021 23:28 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/5 "2021-11-27T23:28:58Z")

</div>

Yes, the physical connections are working great. I have a converter connect as a last device with terminator. I configured the converter as tcp client to send tcp traffic to nodered IP.  
On node red i create a TCP Listner to list all traffic. I need help to filter (for example) only response about specified register like temerature.. For now i isolated only byte refer to slave address and a byte about frame lenght..  
thanks

---

<div class="post-metadata">

### Author: ![TheMiloNet](https://avatars.discourse-cdn.com/v4/letter/t/c68b51/32.png) [@TheMiloNet](https://discourse.nodered.org/u/TheMiloNet)
#### Post date: [27 November 2021 23:31 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/6 "2021-11-27T23:31:11Z")

</div>

Hi, i cannot configure the adapter to Server mode because in the modbus network there is another master (touch panel) that request consinuosly data to slave. I need to sniff and interpretate this traffic

thanks

---

<div class="post-metadata">

### Author: ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)
#### Post date: [28 November 2021 06:23 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/7 "2021-11-28T06:23:28Z")

</div>

I tried this on NR at one stage - but the sheer volume of data was so overwhelming it was very diffcult to do.

In the end as i have a number of different modbus devices that i wish to hack into and control i bit the bullet and purchased a hardware device

[https://ioninja.com/](https://ioninja.com/)

Very much worth it to cut down on the amount of effort and to properly format data etc

Craig

---

<div class="post-metadata">

### Author: ![TheMiloNet](https://avatars.discourse-cdn.com/v4/letter/t/c68b51/32.png) [@TheMiloNet](https://discourse.nodered.org/u/TheMiloNet)
#### Post date: [28 November 2021 16:59 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/8 "2021-11-28T16:59:02Z")

</div>

For now I'm getting important results with wireshark. I hijacked the modbus tcp traffic to a listener on my pc and with wireshark i am analyzing the packet byte by byte.  
I found that the data I want is in a response with funciont code 3, preceded by a request made in a certain way. How can I capture one packet, and if it meets a certain condition, capture the next one? In node red, of course: D

---

<div class="post-metadata">

### Author: ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)
#### Post date: [28 November 2021 21:14 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/9 "2021-11-28T21:14:17Z")

</div>

you could try [node-red-contrib-pcap (node) - Node-RED](https://flows.nodered.org/node/node-red-contrib-pcap) which should be able to do the same as wireshark - but you will need to try to keep the selector tight so as not to flood the process with all the network traffic.

---

<div class="post-metadata">

### Author: ![TheMiloNet](https://avatars.discourse-cdn.com/v4/letter/t/c68b51/32.png) [@TheMiloNet](https://discourse.nodered.org/u/TheMiloNet)
#### Post date: [29 November 2021 11:00 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/10 "2021-11-29T11:00:33Z")

</div>

Unfortunately the installation of the module you recommended fails and I cannot find documentation. I am working on Hass IO.  
What is the cleanest way to collect a TCP packet (currently I split it with buffer parse) and if some data match, I want to capture the next packet. I have identified the Funcion code 3 request packets where the first 10 registers are requested. The slave responds with the 10 registers. Subsequently, the next 10 registers are requested. The slave responds. I would like to associate the request and the response in a single payload (or packet) so I am able to understand the register number. Who helps me?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [28 January 2022 11:01 UTC](https://discourse.nodered.org/t/modbus-sniffer/54290/11 "2022-01-28T11:01:05Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
