Troubleshooting CO2 Sensor Fluctuations on S7-1200 Analog Input

David Krause18 min read
Sensor IntegrationSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Troubleshooting CO2 Sensor Fluctuations on a Siemens S7-1200 Analog Input

When a nondispersive infrared (NDIR) CO2 transmitter is wired into a Siemens SIMATIC S7-1200 analog input, the most common complaint is a stable-looking value that suddenly breaks into a ±10 to ±30 ppm ripple for tens of seconds, then settles again. The pattern is repeatable (every few minutes), it is not random noise, and it survives a power-supply swap. This article walks through every root cause that produces that signature, in the order they should be ruled out, and ends with a verification matrix you can run against your own panel.

Scope. The procedures below apply to S7-1200 CPUs with on-board analog inputs (CPU 1211C / 1212C / 1214C / 1215C / 1217C) and to SM 1231 analog input signal boards/modules (6ES7 231-4xxx, 6ES7 231-5xxx) configured for 0-5 V or 0-10 V voltage measurement. The same logic applies to ET 200SP ST 4 AI modules on PROFINET, but register addresses will differ.

1. Problem Summary

Reported symptoms from the field:

  • 0-5 V output of an NDIR CO2 transmitter wired to a S7-1200 analog input.
  • Value is steady most of the time, then oscillates by approximately ±20 ppm for ~50 seconds.
  • The disturbance returns on a fixed period of ~5 minutes.
  • Swapping the 24 V supply does not change the behaviour.
  • The user is considering a CM 1241 RS485 module and the sensor's Modbus RTU output as a fallback.

The combination of (a) fixed period, (b) limited amplitude, (c) a long stable baseline, and (d) immunity to a new power supply is the diagnostic fingerprint. Random EMI usually looks like a Gaussian band, not a 50-second burst every 5 minutes. That shape almost always points to one of four causes:

  1. The NDIR source lamp duty cycle is being sampled at an unstable phase.
  2. An HVAC or ventilation actuator is cycling on a fixed 5-minute schedule.
  3. A periodic EMI source (wireless device, inverter, relay coil) shares the cable tray.
  4. The PLC is reading the channel faster than the module's update time, producing aliasing.

2. Root Cause Matrix

# Cause Diagnostic signature Where to look
R1 NDIR lamp pulse / self-cal cycle Ripple synchronous with sensor status LED or warm-up current Sensor datasheet "lamp cycle" or "ABC" timing
R2 Shared 24 V with high-inductive load Burst coincides with relay/contactor pull-in Scope the 24 V rail at the sensor terminal
R3 Analog cable in same tray as VFD or motor feeder Burst coincides with motor run signal Cable routing inspection
R4 Wireless / RF interferer on periodic duty Disappears when sensor is bench-tested on a short lead Cell phone, Wi-Fi AP, RFID reader proximity
R5 Update-time aliasing in S7-1200 ADC Ripple frequency = f_sample − f_signal Module integration time vs. OB1 scan time
R6 Poor shield termination / ground loop Reading changes when you disconnect shield at one end Shield bonding at the cabinet gland
R7 Quantisation on a low-resolution input Step changes of 1-2 LSB without physical change Module part number vs. ppm-per-LSB
R8 Sensor end-of-life or condensation on cell Drift that grows over hours/days, not minutes Sensor age, humidity spec

3. Verify the Sensor Output Directly with a DMM

Before changing anything in TIA Portal, prove that the analog output itself is stable. Disconnect the signal wire from the S7-1200 terminal block and connect a true-RMS digital multimeter (DMM) directly across the sensor's Vout and GND terminals at the sensor head, not at the cabinet end.

  1. Set the DMM to DC volts, 0-10 V range, ≥ 6½ digit resolution if available.
  2. Log the value every 5 seconds for at least 15 minutes (3× the suspected 5-minute period).
  3. Compute the standard deviation of the reading.

For a 0-5 V sensor spanning 0-2000 ppm (2.5 mV/ppm), a stable sensor with good wiring will show a standard deviation of < 1 mV, i.e. < 0.4 ppm of noise. If the DMM shows the same ±20 ppm burst, the sensor itself is the source. If the DMM shows a flat line, the disturbance is between the sensor and the PLC.

Why a DMM and not the PLC? A DMM integrates over hundreds of milliseconds to seconds, which averages out the kind of periodic ripple the S7-1200 sees. If the DMM is flat and the PLC wobbles, the cause is downstream — cable, shielding, grounding, or ADC integration time.

4. Cable Routing, Shielding, and Grounding

Voltage-mode analog signals (0-5 V, 0-10 V) are far more sensitive to common-mode noise than current loops (4-20 mA). For a 0-5 V sensor, every millivolt of coupled noise is 0.4 ppm of apparent CO2 change. A 2 V peak motor drive transient coupled through a parallel cable can easily deliver 50 mV of common-mode shift at the input terminal.

4.1 Physical separation

  • Maintain ≥ 200 mm (8 in) between the analog signal cable and any AC power, VFD output, or DC contactor coil wiring. Cross at 90° if intersection is unavoidable.
  • Do not run the analog cable in the same conduit, trunking, or cable tray as a Variable Frequency Drive (VFD) feeder. If they must share a tray, use a continuous metal divider.

4.2 Cable type

  • Use twisted pair, overall foil + braid shielded cable (e.g. Belden 8761, Lapp EVC CY).
  • Minimum conductor size 0.34 mm² (22 AWG) for runs up to 50 m.
  • Keep total run length under 50 m for 0-5 V signals without additional buffering; use 4-20 mA current loop or RS485 for longer distances.

4.3 Shield termination

Terminate the shield at one end only, typically at the cabinet ground bar where the PLC DIN rail is bonded to protective earth (PE). Floating the shield at the sensor end (or bonding at both ends) is the most common cause of ground-loop oscillation in plant installations.

Sensor end             Cabinet end (PLC)
  |                       |
  +--- Vout (twisted) ---+ AI+ on SM 1231
  +--- GND  (twisted) ---+ AI- (Mana) on SM 1231
  +--- (shield)          +- PE bar, 360° gland
        NOT connected        bonded here

For a S7-1200 SM 1231 module, the analog ground reference terminal (Mana) must be tied to the same 24 V common that supplies the sensor. The Mana terminal is not the same as PE; it is the analog reference for the ADC. Refer to the S7-1200 System Manual for the exact terminal assignments of your signal board.

5. Power Supply Quality

The user's first action was a power-supply swap, which suggests the suspicion was already on the 24 V rail. A regulated industrial supply (Siemens SITOP 6EP1334-3BA10, Phoenix Contact QUINT, or Meanwell NDR) is normally adequate, but a few subtle issues remain:

  • Common-mode noise on 0 V / 24 V: If the sensor shares its 24 V return with a relay, solenoid, or VFD fan, the return path is not at 0 V when that load switches. Use a separate fused branch from the supply and star-point the 0 V at the supply terminal.
  • Peak-to-peak ripple > 100 mV: Verify with an oscilloscope on DC coupling, 20 MHz bandwidth limit. Most NDIR sensors specify < 50 mV ripple tolerance on the supply.
  • Inrush of an NDIR lamp: Many CO2 modules pulse their IR source at 1-4 Hz; the inrush of that pulse is a small but real load step. If the supply has poor transient response (some low-cost switching supplies), the 24 V sags during the pulse and the output voltage droops. A 1000 µF / 35 V electrolytic at the sensor terminal smooths it.

6. NDIR Sensor Behavior and the 5-Minute Cycle

NDIR CO2 sensors do not produce a DC voltage in the way an electrochemical sensor does. They pulse an infrared emitter, synchronously detect the transmitted IR at a photodiode, and demodulate to a CO2 concentration. The pulse, the demodulation, and any Automatic Baseline Correction (ABC) routine all run on internal timers, typically 1 Hz to 4 Hz for the lamp and 24 h to 7 d for ABC.

A 5-minute period is too short for ABC but is consistent with:

  1. An HVAC or fresh-air damper cycling on a fixed schedule (CO2 rises for 4 minutes, falls for 1 minute as the damper opens).
  2. A building-management scheduled event such as a night-purge or a print/copy room cycle.
  3. The sensor's internal "auto-zero" pulse — some low-cost NDIR modules run a 30-60 second re-zero every 5 minutes when ABC is enabled. The reading briefly destabilises during the re-zero window.

For the underlying physics of NDIR measurement, including the pulsed source and synchronous detection, see the Analog Devices technical article Complete Gas Sensor Circuit Using Nondispersive Infrared (NDIR). The article explains why the detector output is a demodulated waveform, not a smooth DC level, and why the demodulation phase must be considered when sampling.

6.1 Confirming an HVAC source

Plot the CO2 reading against the actuator command (fan, damper) in TIA Portal using a trace or a data log. If the CO2 swing lines up with the actuator state change, the sensor is reporting a real physical event and the "noise" is a measurement of room air, not an instrument fault. In that case, longer filtering will only delay the reading — fix the ventilation, not the signal chain.

7. TIA Portal Hardware Smoothing

The S7-1200 analog input modules (SM 1231 family) support a Smoothing parameter in the device configuration. Smoothing is averaging performed in the module's hardware/firmware before the value is presented to the PLC, so it is the cheapest and most effective first step.

  1. In TIA Portal, open Devices & Networks and select the S7-1200 CPU.
  2. Open Device View and click the analog input channel (AI0-AI7) the sensor is wired to.
  3. In the Properties > Input tab, locate the Smoothing group.
  4. Change the drop-down from None to one of the available levels.
Smoothing level Values averaged Effective integration Typical use
None 1 1 × update time Fastest response, highest noise
Weak 2 ~2 × update time Light noise on clean installations
Medium 4 ~4 × update time Most HVAC / IAQ applications
Strong 16-32 (module dependent) ~16-32 × update time Very slow signals, > 10 s response

For SM 1231 13-bit modules (6ES7 231-4HD32, 6ES7 231-4HF32) the standard Smoothing levels are None / Weak / Medium / Strong. For SM 1231 16-bit modules (6ES7 231-5ND32, 6ES7 231-5PF32) an additional Very Strong level averaging 32 values may be available, but always confirm against the module's properties dialog in your specific TIA Portal version (V15, V16, V17, V18).

Update time vs. smoothing. The integration time of the ADC and the smoothing level are stacked. Raising smoothing from None to Strong on a 4-channel SM 1231 13-bit can extend the per-channel update time from ~1.25 ms to ~80 ms. For a non-critical IAQ loop, the extra 80 ms is irrelevant. For a fast PID loop, it is unacceptable. Choose accordingly.

8. Software Filtering in STEP 7 (SCL)

Hardware smoothing may not be enough if the burst is fast (1-2 seconds) and the module is set to fast update. A software filter in the PLC adds a second line of defence. The three common approaches are:

8.1 Moving average (good general-purpose filter)

// FB_CO2_Filter, written in SCL for S7-1200 / TIA V17
// Input:  rRaw      (REAL, scaled 0-2000 ppm)
//         bReset    (BOOL)
//         iWindow   (INT, e.g. 16)
// Output: rFiltered (REAL)

VAR
    aBuffer : ARRAY[0..63] OF REAL;
    iIndex  : INT := 0;
    rSum    : REAL := 0.0;
    iCount  : INT := 0;
END_VAR

BEGIN
    IF bReset THEN
        FOR iIndex := 0 TO 63 DO aBuffer[iIndex] := 0.0; END_FOR;
        iIndex := 0;
        rSum   := 0.0;
        iCount := 0;
    END_IF;

    rSum := rSum - aBuffer[iIndex] + rRaw;
    aBuffer[iIndex] := rRaw;
    iIndex := (iIndex + 1) MOD 64;

    IF iCount < iWindow THEN iCount := iCount + 1; END_IF;

    IF iWindow < 1 THEN iWindow := 1; END_IF;
    rFiltered := rSum / INT_TO_REAL(iCount);
END_FUNCTION_BLOCK

8.2 Exponential filter (single-value, low memory)

// rFiltered = rFiltered + alpha * (rRaw - rFiltered)
// alpha = 0.1  -> slow, very smooth
// alpha = 0.5  -> medium
// alpha = 1.0  -> no filtering
rFiltered := rFiltered + 0.15 * (rRaw - rFiltered);

An exponential filter with α = 0.15 is a good default for a 1 Hz sample rate. It rejects a 50-second burst almost entirely while keeping a step change visible within ~20 seconds.

8.3 Median filter (rejects single-sample spikes)

A 5-point median filter will reject a 1-sample transient completely. This is the right choice if the disturbance you are chasing is a single-cycle impulse from a relay, not a 50-second sustained swing.

Stack the filters. Use hardware Smoothing = Medium and a software exponential filter. Hardware smoothing removes high-frequency noise on the wire; the software filter shapes the response of the displayed/process value. Do not rely on software filtering alone — the S7-1200 ADC's least significant bit at 0-5 V spans 1.25 mV (13-bit) or 0.15 mV (16-bit), and 13-bit modules will produce 0.5-1 ppm of quantisation noise at 2000 ppm full scale.

9. Synchronised Sampling with a Time-Interrupt OB (OB 30)

The 50-second burst every 5 minutes is a slow event, but the S7-1200's main scan (OB 1) is much faster — typically 10-50 ms. Reading the ADC thousands of times per second and throwing the data away is wasteful and can cause aliasing if the OB 1 cycle is not a clean multiple of the disturbance period. Better practice is to read the analog value on a fixed schedule using a cyclic interrupt OB.

  1. In TIA Portal, right-click the CPU under Program blocks and choose Add new block > Organization block > Cyclic interrupt.
  2. Select OB 30 and set the Cycle time to e.g. 1000 ms (1 second). The S7-1200 supports OB 30 in the range 1-60 000 ms.
  3. Place the analog-input read (e.g. SCALE or the NORM_X / SCALE_X pair, or the symbolic tag from the analog channel) inside OB 30.
  4. Run the moving-average / exponential filter as a separate FB called from OB 30, so the filter is updated at exactly 1 Hz.

The advantage of OB 30 is twofold: the analog value is updated at a known rate, and the filter coefficients are designed for that exact rate. The disadvantage is that OB 30 runs in addition to OB 1, so any process value visible to OB 1 must be made accessible via a global DB or a tag.

10. Update Time and Module Selection

The on-board analog inputs of a CPU 1214C / 1215C / 1217C are 12-bit (typical) and update at a fixed rate. The SM 1231 family offers two main resolutions:

Part number Channels Resolution Voltage ranges Notes
6ES7 231-4HD32-0XB0 4 AI 13-bit + sign ±10 V, ±5 V, ±2.5 V, 0-20 mA, 4-20 mA Cost-effective, 0-5 V must be scaled from 0-10 V
6ES7 231-4HF32-0XB0 8 AI 13-bit + sign ±10 V, ±5 V, ±2.5 V Higher density
6ES7 231-5ND32-0XB0 4 AI 15-bit + sign ±10 V, ±2.5 V, 0-20 mA, 4-20 mA Use for 0-5 V via software scaling
6ES7 231-5PF32-0XB0 8 AI 16-bit ±10 V, 0-10 V, ±5 V, 0-5 V (firmware dep.) True 0-5 V hardware range, no software scaling error
0-5 V on a 0-10 V module. Most SM 1231 modules do not expose a native 0-5 V range. If your module is 0-10 V, you must scale the integer to the engineering range in the PLC: rEng = (rRaw / 27648.0) × 5000.0 mV for a 0-10 V module, or rEng = (rRaw / 27648.0) × 2000.0 ppm if the sensor spans 0-5 V = 0-2000 ppm. The 16-bit module (5PF32) at 0-10 V gives ~0.36 mV / LSB; at 0-5 V it gives ~0.18 mV / LSB. Use the 16-bit module if 0-5 V is critical.

11. Escalating to RS485 / Modbus RTU

If the analog path cannot be made stable — typically because the cable run is long, the environment is electrically hostile, or the sensor's analog output is genuinely noisy — the serial digital path is the proper fix. The S7-1200 supports Modbus RTU master on the CM 1241 RS485 communication module.

11.1 Required hardware

  • CM 1241 RS485 (6ES7 241-1CH30-1XB0, superseded by 6ES7 241-1CH32-0XB0) for Modbus RTU master.
  • RS485 twisted pair (Belden 3106A or equivalent), 120 Ω termination at both ends.
  • CO2 sensor with Modbus RTU output (most modern IAQ sensors offer this).

11.2 TIA Portal configuration

  1. Install the CM 1241 in the device configuration and set the port to RS485 Half-Duplex.
  2. In Properties > Port Configuration, set baud rate, parity, and stop bits to match the sensor (commonly 9600 8N1 or 19200 8N1).
  3. Call MB_MASTER or Modbus_Master (TIA V16+) from a cyclic OB (OB 1 or OB 30) and read the input register holding the CO2 value (commonly register 0x0001 or 0x0003 depending on the sensor vendor).
  4. Set the poll interval to 1-5 seconds. Most NDIR sensors internally update the Modbus register at 1 Hz regardless of how often you poll.

The advantage of the digital path is that the 16-bit or 24-bit value from the sensor is delivered verbatim, with a CRC-16 check. The analog cable, shield, ground loop, and ADC quantisation are removed from the equation entirely.

12. Step-by-Step Diagnostic Procedure

Run the following sequence top to bottom. Each step either fixes the issue or eliminates a hypothesis.

  1. DMM at the sensor head for 15 min. Confirms whether the analog output is intrinsically stable. If not, the sensor or its power is at fault.
  2. Move the analog cable out of the cable tray. Run a temporary 1 m shielded lead back to the PLC. If the ripple disappears, the original cable was picking up interference. Re-route the cable permanently and apply the cable rules in §4.
  3. Bond the shield at one end only, at the cabinet. Disconnect the shield at the sensor end. If the ripple drops, the original termination was a ground loop.
  4. Power the sensor from a separate 24 V branch with its own fuse. Star-point the 0 V at the supply terminal.
  5. Set Hardware Smoothing = Medium in the analog channel properties, recompile, and download to the PLC.
  6. Add an exponential filter (α = 0.15) in an FB called from a 1 Hz OB 30.
  7. Correlate the ripple with HVAC or BMS events by trending the CO2 value against a digital input that mirrors a fan/damper command. If the ripple is a real physical event, fix the ventilation; do not over-filter the signal.
  8. Check the sensor's datasheet for "lamp cycle" or "ABC period". Some sensors (e.g. certain Senseair K30, MH-Z19, Winsen MH-Z14 variants) emit a noisy reading during the 30-60 second auto-zero. Disable ABC if the application does not require it.
  9. Upgrade the SM 1231 module to a 16-bit variant (5PF32) if the existing module is 13-bit and the quantisation is significant.
  10. Move to RS485/Modbus RTU via a CM 1241 if all of the above fail to deliver ±2 ppm stability.

13. Verification Matrix

Test Expected result if root cause is fixed Measurement
DMM at sensor head, 15 min log Standard deviation < 1 mV DMM in DCV mode, datalogger
PLC reading with Smoothing = Medium, no software filter Ripple < ±2 ppm Watch table in TIA Portal, online
PLC reading with Smoothing = Medium + exp filter α = 0.15 Ripple < ±0.5 ppm steady-state Trace on HMI or data log
Reading step response to a 500 ppm gas injection 10-90 % rise time < 30 s with above filter Span gas test
CM 1241 Modbus RTU readout of same sensor Identical to analog path within 1 % FS Compare PEW analog vs. Modbus input word
Final field note. A ±20 ppm swing every 5 minutes is large enough to be a real physical change in the room, not a sensor artefact. Before adding any more filtering, spend ten minutes confirming that the room's CO2 is in fact changing on that schedule — open a window, run the exhaust fan, hold your breath next to the sensor. If the room CO2 is genuinely swinging, the right fix is process, not PLC.

What is the most common cause of a 5-minute periodic fluctuation on a S7-1200 CO2 input?

An HVAC or fresh-air damper cycling on a fixed schedule, or the sensor's internal automatic baseline correction (ABC) routine that runs every few minutes on some low-cost NDIR modules. Confirm by trending the CO2 value against a digital input that mirrors the fan or damper command before adding any filtering.

Which TIA Portal smoothing level should I use for a 0-5 V CO2 sensor on a SM 1231 module?

Start with Medium (4 values averaged). It removes high-frequency cable noise without adding more than ~80 ms of module update-time delay. Move to Strong only if Medium is insufficient and the application can tolerate a ~1 s response time.

Can I read a 0-5 V sensor on a S7-1200 SM 1231 that only has 0-10 V or ±10 V range?

Yes. The 0-5 V signal will be read correctly as long as it stays within the module's voltage range. Scale the raw integer in the PLC: rEng_mV = (PEW / 27648) × 10000 for a 0-10 V module, then multiply by 0.4 to obtain ppm if the sensor spans 0-5 V = 0-2000 ppm. For best accuracy, use the 16-bit SM 1231 (6ES7 231-5PF32-0XB0) which exposes a true 0-5 V hardware range.

Do I need a CM 1241 RS485 to use the sensor's Modbus output?

Yes, for Modbus RTU on a S7-1200 you need a CM 1241 RS485 (6ES7 241-1CH30-1XB0 or 6ES7 241-1CH32-0XB0). Configure the port at 9600 8N1 (typical for CO2 sensors), call MB_MASTER or Modbus_Master from a cyclic OB, and read the CO2 holding register. The serial path eliminates analog cable noise, ADC quantisation, and ground loops.

How do I stop a ground loop on a S7-1200 analog input?

Terminate the cable shield at one end only, normally at the cabinet ground bar bonded to PE. Disconnect the shield at the sensor end. Bond the SM 1231 Mana (analog ground) terminal to the same 24 V common that supplies the sensor. If the reading still drifts when you touch the shield, your shield is bonded at both ends — remove one.

Back to blog