Port 514: Syslog

UDP 514 is the port for Syslog. Only to your log collector; it is unauthenticated.

Port 514 at a glance
ServiceSyslog
ProtocolUDP
Exposure riskMedium: expose with care
RangeWell-known (0–1023): binding needs root/admin on Unix

Port 514 is UDP-only. UDP has no handshake, so no online checker can reliably tell open from filtered; test with the service's own client.

What port 514 does

Routers, firewalls and servers send log lines to a central collector on UDP 514. TCP 514 (rsh) and syslog over TLS on 6514 are also used.

Should port 514 be open?

Only to your log collector; it is unauthenticated.

Find what's listening on port 514

  • Linux: sudo ss -tulpn | grep :514
  • macOS: sudo lsof -nP -i :514
  • Windows: netstat -ano | findstr :514, then look up the PID in Task Manager.

Open or block it in a firewall

  • ufw: sudo ufw allow 514/udp (or deny)
  • firewalld: sudo firewall-cmd --add-port=514/udp --permanent && sudo firewall-cmd --reload
  • Windows: New-NetFirewallRule -DisplayName "Port 514" -Direction Inbound -Protocol UDP -LocalPort 514 -Action Allow

Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.

Questions about port 514

What is port 514 used for?
Syslog. Routers, firewalls and servers send log lines to a central collector on UDP 514. TCP 514 (rsh) and syslog over TLS on 6514 are also used.
Is port 514 TCP or UDP?
UDP. Syslog uses UDP port 514.
Is it safe to open port 514?
Medium: expose with care. Only to your log collector; it is unauthenticated.
How do I check if port 514 is open?
Port 514 is UDP-only, which has no handshake, so an online TCP checker can't confirm it. Use the service's own client to test, and check what is listening locally with ss -ulpn | grep :514 (Linux) or netstat -ano | findstr :514 (Windows).

← Port 465 (SMTPS) · Port 587 (SMTP submission) →