Skip to main content

Port Details

Port
514
Transport
UDP / TCP
Service
Syslog
IANA service name
syslog (udp), shell (tcp)
Range
System port (0-1023)
Related ports
6514

Security Exposure

Syslog over UDP has no sender authentication, so any host that reaches the collector can inject forged log entries. RFC 5426 states that using this transport on an unsecured network is not recommended. A TCP 514 listener points to rsh, the remote shell service that IANA lists on that port with automatic authentication.

Hardening

  • +Accept UDP 514 only from known log sources on internal or management networks.
  • +Use syslog over TLS on TCP 6514 (RFC 5425) for logs that cross untrusted networks.
  • +Disable rsh and remove the service; use SSH for remote command execution.
  • +Size and rate-limit the collector so a flood of messages does not drop legitimate logs.

Monitoring

Alert when a collector receives syslog from source addresses outside the approved device inventory, or when expected sources go silent. Flag any host listening on TCP 514.

Tools for Auditing and Monitoring Syslog

Graylog

Free / Commercial
SIEM Tools

Open core log management platform with SIEM features, event definitions, and alerting.

LicenseSSPL-1.0 (open core)
PlatformWeb, Linux

Splunk

Free / Commercial
SIEM Tools

Search-driven SIEM and observability platform, owned by Cisco since 2024.

LicenseProprietary
PlatformWeb, Linux, Windows

Wazuh

Free / Commercial
SIEM Tools

Open-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.

LicenseGPL-2.0-only with OpenSSL linking exception
PlatformLinux, Windows, macOS, Solaris, AIX, HP-UX

Frequently Asked Questions

Is syslog TCP or UDP 514?→

Syslog uses UDP 514 (RFC 5426). IANA assigns TCP 514 to the rsh shell service, and syslog over TLS uses TCP 6514 per RFC 5425.

Is syslog on port 514 encrypted?→

No. RFC 5426 says the UDP transport provides no strong sender authentication and recommends IPsec or other protection on unsecured networks; RFC 5425 defines syslog over TLS.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 514 is not guaranteed to be Syslog. Exploited-in-the-wild data from the CISA KEV catalog (CC0).