Port 514 — Syslog
UDP well-known
What runs on port 514
Remote logging.
Security considerations
UDP syslog has no authentication and no delivery guarantee. Use TLS syslog on 6514 for anything that matters.
Checking whether something is listening
# Linux / macOS — what is bound to the port
sudo lsof -i :514
sudo ss -lntp | grep :514
# Windows
netstat -ano | findstr :514
Get-NetTCPConnection -LocalPort 514
# is it reachable from outside?
nc -zv example.com 514
curl -v telnet://example.com:514
Freeing the port
# find the process, then stop it
sudo lsof -ti :514 | xargs kill # Linux / macOS
netstat -ano | findstr :514 # note the PID, then:
taskkill /PID <pid> /F # Windows
Should this port be open to the internet?
Usually not. Expose it only if a specific external client needs it, and restrict by source address where you can.
Quick reference
| Port | 514 |
| Protocol | UDP |
| Service | Syslog |
| Range | Well-known (0–1023) — binding requires root on Unix |
Frequently asked questions
What is port 514 used for?
Remote logging.
Is it safe to open port 514?
UDP syslog has no authentication and no delivery guarantee. Use TLS syslog on 6514 for anything that matters.
How do I check if port 514 is open?
Locally, sudo lsof -i :514 on macOS or Linux, or netstat -ano | findstr :514 on Windows. From outside, nc -zv host 514 tells you whether anything answers.
Why do I get "address already in use" on port 514?
Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :514 and stop it, or configure your application to use a different port.
Can I change the port this service uses?
Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.