Port 514: Syslog
UDP 514 is the port for Syslog. Only to your log collector; it is unauthenticated.
| Service | Syslog |
|---|---|
| Protocol | UDP |
| Exposure risk | Medium: expose with care |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
Port 514 is UDP-only. UDP has no handshake, so no online checker can reliably tell open from filtered; test with the service's own client.
What port 514 does
Routers, firewalls and servers send log lines to a central collector on UDP 514. TCP 514 (rsh) and syslog over TLS on 6514 are also used.
Should port 514 be open?
Only to your log collector; it is unauthenticated.
Find what's listening on port 514
- Linux:
sudo ss -tulpn | grep :514 - macOS:
sudo lsof -nP -i :514 - Windows:
netstat -ano | findstr :514, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 514/udp(ordeny) - firewalld:
sudo firewall-cmd --add-port=514/udp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 514" -Direction Inbound -Protocol UDP -LocalPort 514 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 514
What is port 514 used for?
Syslog. Routers, firewalls and servers send log lines to a central collector on UDP 514. TCP 514 (rsh) and syslog over TLS on 6514 are also used.
Is port 514 TCP or UDP?
UDP. Syslog uses UDP port 514.
Is it safe to open port 514?
Medium: expose with care. Only to your log collector; it is unauthenticated.
How do I check if port 514 is open?
Port 514 is UDP-only, which has no handshake, so an online TCP checker can't confirm it. Use the service's own client to test, and check what is listening locally with
ss -ulpn | grep :514 (Linux) or netstat -ano | findstr :514 (Windows).