A modern diesel broadcasts more than two thousand data points a second across engine, transmission, brakes and aftertreatment, and every one of them speaks J1939. Access to that stream is rarely the problem — plenty of platforms read it. What happens to a fault after it arrives is the problem, because J1939 faults arrive in clusters and most systems treat each one as an independent event. A low diesel exhaust fluid quality issue commonly surfaces as four codes in a single session. A failed NOx sensor cascades into SCR efficiency, dosing and inducement codes until eight are showing. Fix the sensor and all eight disappear. Treat them individually and a ninety-minute job becomes a full day, with eight work orders documenting one repair. Send us a live fault list from one truck and we'll show you where the cascade starts — it almost always collapses to one or two root causes.
Integration · J1939 CAN Bus Data
J1939 CAN Bus Data Integration for Heavy-Truck Fleets
Reading the bus is the easy part. Grouping cascaded faults, ranking by the severity the ECM already assigned, and raising one work order for one repair is the part that saves a day.
SPN
FMI
OC
SA
Lamp status
Four Codes, One Fault
The single most consequential thing to understand about heavy-duty diagnostics, and the thing most integrations get wrong.
What the dashboard reports
SPN 3868 — aftertreatment fluid
SPN 4364 — SCR conversion efficiency
SPN 5246 — inducement / operator warning
SPN 1569 — torque derate
collapses to
One originating fault, upstream
The derate is almost never the real problem. Published guidance for 2010-and-later emissions engines is to find the originating fault upstream of the derate rather than chasing each code individually — the derate is the engine's response, not its cause.
This matters commercially as much as technically. A platform that auto-creates a work order per fault code generates eight jobs for one repair — inflating open-work counts, distorting cost per asset and sending a technician to chase symptoms. Recognising a cascade and raising one job against the root is worth more than any amount of dashboard polish.
Four Fields Arrive. Most Systems Keep Two.
Every fault carries four components, and the two usually discarded are the ones that make trending possible.
SPN
What failed
A 19-bit suspect parameter number. SPN 110 is coolant temperature, 3361 the DEF dosing unit, 4094 the DEF tank level, 791 the left steer wheel speed sensor. Thousands exist; most fleets meet the same fifteen to twenty repeatedly.
FMI
How it failed
Thirty-two standard failure modes. FMI 0 is data valid but above normal, most severe. FMI 5 is current below normal or an open circuit. The same component with a different mode is a different job entirely.
OC
How often
Occurrence count. A fault showing hundreds of occurrences is a different conversation from a first event — and this is the field most commonly dropped at capture, taking your ability to spot intermittents with it.
SA
Which module
Source address. Faults come from different control units on the same truck — engine, aftertreatment, braking. Without it you cannot tell three separate problems from one cascade.
Worth putting to whatever you currently run: does it store all four, or a parameter number and a description? A system keeping only the first two can display faults but cannot trend them, cannot distinguish a recurring intermittent from a new event, and cannot group a cluster by the module that produced it.
The Engine Already Ranked Them
Severity is broadcast alongside the codes as lamp status — the most underused field in heavy-duty telematics.
Red stop
Damage or unsafe operation if you continue
Oil pressure loss, coolant loss, dangerous overtemperature. Stop safely, log the code, arrange transport. This outranks everything else in the active list without exception.
Protect
The ECU is already limiting power
Protective mode engaged, with behaviour varying by manufacturer. Treat as intervention already underway — the truck is defending itself from something you have not identified yet.
Amber warning
A fault exists, no shutdown required
Borderline sensor readings or early-stage degradation. Complete the trip, then diagnose — because left unresolved it frequently escalates to red within a shift or two. The ECM warned you before it had to shout.
Malfunction
Emissions-related
Aftertreatment, EGR, NOx sensor or DEF quality. Not an operational emergency, but ignoring it leads to derate strategies — typically a speed limit first, then idle-only — plus exposure at emissions inspection.
The line to repeat to anyone who dismisses dashboard lamps: the colour is not decoration — it maps to a severity tier the ECM assigned, and it tells you how much time you have. A platform that alerts every fault identically has thrown away a ranking the engine already performed, leaving a human to re-derive it under pressure.
47
stored codes
Sitting unread across one 52-vehicle fleet, for weeks. How many in yours?
Almost nobody knows, because stored codes never announce themselves — they accumulate quietly in a dashboard nobody opens between incidents. That fleet went on to prevent three turbo failures at roughly $3,200 each in the following four months, from data they already had. Pull your stored list and count it; that number is your starting position.
The Codes You Will Actually See
Thousands are defined. On a working fleet the same handful recur, and on 2010-and-later engines aftertreatment dominates shop volume.
Swipe to see all columns
Emissions requirements from 2010 onward added particulate filters, selective catalytic reduction, DEF systems and NOx sensors — each with its own sensors and control loops generating codes when out of specification. That is why aftertreatment now dominates shop volume and why clusters are the norm rather than the exception on any engine built since.
The Same Code Getting Worse Is a Countdown
The most genuinely predictive signal on a heavy truck, and it needs no additional hardware.
FMI 16
FMI 0
Above normal, moderate — easy to dismiss while the truck runs fine
2–3 weeks
Dangerously above normal, most severe — now a red lamp and a stopped truck
That progression is reported at roughly two to three weeks on common parameters, which is a real maintenance window sitting inside data you already collect. Trending failure mode against parameter over time turns fault codes from an alerting system into a forecasting one — but only where occurrence counts and history survive each refresh rather than being overwritten.
Active, Stored, and the Mistake That Erases Both
Two message types and one practice worth writing into your shop procedure.
Active
Broadcast continuously by every module currently reporting a fault, carrying the codes plus the lamp status that ranks them. This is what a cellular-connected integration streams, appearing within seconds of the fault triggering.
Stored
Previously active codes no longer present — requested rather than broadcast. This is the diagnostic history and where intermittent faults live. A truck with nothing active and a long stored list is telling you something worth reading.
Non-negotiable
Capture everything before anyone clears anything
The full active and stored list — parameter, failure mode, occurrence count and source address for every entry, plus lamp status. Clearing codes first destroys the evidence, and on an intermittent that recurs three weeks later the diagnosis then starts from nothing. An integration that streams and retains as faults occur makes the clearing decision harmless.
Inside Fleet Rabbit: One Cascade, Resolved
The four-code cluster from the top of this page, followed through the platform.
Arrives with every field intact
Streamed off the bus with parameter, failure mode, occurrence count, source address and lamp status preserved — plus location and timestamp, so a roadside decision has context rather than just a number.
Translated into plain language
Not a log line reading SPN 3361 FMI 5, but the DEF dosing unit with an open circuit or no current flow. A dispatcher makes a run-or-stop call in seconds instead of phoning a technician to interpret a number.
Grouped as one event
Related aftertreatment codes held together rather than fired as four alerts, with the derate flagged as downstream rather than independent. This is the step that prevents eight work orders for one repair, and the one worth testing against anything you compare.
Ranked by the ECM's own severity
Red stop lamps and engine-protection failure modes go to the top regardless of queue position. Amber and emissions faults sit behind them — the triage a shop would apply by hand if it had the time.
One work order, raised against the root
Carrying the asset, current odometer and engine hours, open defects, previous occurrences of the same parameter and the full cluster as diagnostic context — so the technician starts upstream rather than at the derate.
History survives the repair
Occurrence counts and prior events stay on the asset record, so the same parameter returning in six weeks reads as a repeat rather than a fresh problem, and an escalating failure mode is visible as a trend.
Any platform can display four codes.
Far fewer will tell you they are one problem — and that difference decides whether a technician starts at the fluid quality fault or at the derate, which is where the wasted day comes from. For protocol background, see our
J1939 and J1708 diagnostics guide.
Five Triage Rules Worth Posting in the Shop
Drawn from technician practice. They work whether you automate them or not.
01A red stop lamp outranks everything else in the active list, without exception.
02Any failure mode of 0 or 1 is engine-protection territory — priority regardless of what else is present or how the truck feels to drive.
03Never begin diagnosis at a derate code. Look upstream at whatever DPF, NOx or DEF condition triggered it.
04Assume aftertreatment codes appearing together share one root. Fix that and the rest clear themselves.
05Capture the full active and stored list — all four fields plus lamp status — before clearing anything at all.
Connect three trucks and watch how a real cluster behaves
Free, no card, no time limit. Put three J1939-equipped units on it and see what happens when an aftertreatment cluster actually arrives — whether it fires as four alerts or resolves into one job, whether the derate is identified as downstream, and whether occurrence counts survive. Most fleets find at least one stored code on those three vehicles that has been sitting unread, which tends to settle the question without any further argument.
Frequently Asked Questions
Why do we get so many codes at once?
Because modern aftertreatment cascades. Emissions requirements from 2010 onward added particulate filters, selective catalytic reduction, DEF systems and NOx sensors, each with its own sensors and control loops producing codes when out of specification. A single low DEF quality event commonly surfaces as four codes in one session, and a failed NOx sensor can cascade into SCR efficiency, dosing and inducement codes. Fix the originating fault and the downstream codes clear.
Where should a technician start on a multi-code truck?
Upstream of the derate, always. A torque derate code is almost never the real problem — it is the engine's response to something the DPF, NOx or DEF system reported first. Published guidance for 2010-and-later engines is to find the originating fault rather than chasing each code individually, because treating them independently is what turns a ninety-minute job into a full day.
What do the four code fields mean?
The suspect parameter number identifies what failed — coolant temperature, DEF dosing unit, wheel speed sensor. The failure mode identifier describes how, across thirty-two standard modes, with FMI 0 meaning data valid but above normal and most severe, and FMI 5 meaning current below normal or an open circuit. Occurrence count tells you how often it has triggered, and source address tells you which control module reported it. The last two are the ones most commonly discarded.
How do we know which faults are urgent?
The engine already told you. Lamp status is broadcast alongside the codes and maps to a severity tier the ECM assigned — red stop meaning damage or unsafe operation if you continue, protect meaning power is already being limited, amber meaning a fault that can wait until the trip ends, and the malfunction indicator meaning emissions-related. Any failure mode of 0 or 1 is engine-protection territory regardless of what else is present.
Can J1939 data actually predict failures?
To a useful degree, without additional sensors. The same parameter escalating through failure modes is a countdown — an above-normal-moderate reading today is reported to become dangerously-above-normal within roughly two to three weeks, and amber faults left unresolved frequently escalate to red within a shift or two. Both depend on occurrence counts and history being retained rather than overwritten at each refresh.
What is the difference between active and stored codes?
Active faults are broadcast continuously by any module currently reporting a problem. Stored faults are previously active codes no longer present, requested rather than broadcast, and they hold the diagnostic history where intermittent faults live. Capture both — all four fields plus lamp status — before clearing anything, because clearing first destroys the only record of what the truck was reporting.
What does this save in practice?
Diagnostic time, by starting at the root rather than the derate. And failures caught early from data already being collected — one 52-vehicle fleet found 47 stored codes sitting unread for weeks, then prevented three turbo failures at roughly $3,200 each over the following four months. Set against a head gasket failure costing $6,800 plus recovery and two days of downtime after a coolant temperature code went unread, the arithmetic is not close. Connect three trucks free and count your own stored codes first.
Don't Chase Eight Codes. Find the One.
Heavy-duty faults arrive in clusters and the engine has already ranked them. Keep all four fields rather than a parameter and a label, use the lamp status the ECM broadcast instead of re-deriving urgency by hand, never begin diagnosis at a derate, capture the full active and stored list before anyone clears anything — and raise one work order against the root, because eight jobs documenting one repair is a reporting problem as well as a wasted day.