Port 514: Syslog over UDP (and rsh on TCP)
UDP 514 is the well-known port for syslog, which network devices, servers and appliances use to send log messages to a central collector. RFC 5426 requires syslog receivers to accept datagrams on UDP 514. On TCP, IANA assigns 514 to the legacy BSD remote shell (rsh) service, which IANA describes as remote command execution with automatic authentication.
Port Details
Security Exposure
Syslog over UDP has no sender authentication, so any host that reaches the collector can inject forged log entries. RFC 5426 states that using this transport on an unsecured network is not recommended. A TCP 514 listener points to rsh, the remote shell service that IANA lists on that port with automatic authentication.
Hardening
- +Accept UDP 514 only from known log sources on internal or management networks.
- +Use syslog over TLS on TCP 6514 (RFC 5425) for logs that cross untrusted networks.
- +Disable rsh and remove the service; use SSH for remote command execution.
- +Size and rate-limit the collector so a flood of messages does not drop legitimate logs.
Monitoring
Alert when a collector receives syslog from source addresses outside the approved device inventory, or when expected sources go silent. Flag any host listening on TCP 514.
Tools for Auditing and Monitoring Syslog
Graylog
Free / CommercialOpen core log management platform with SIEM features, event definitions, and alerting.
Splunk
Free / CommercialSearch-driven SIEM and observability platform, owned by Cisco since 2024.
Wazuh
Free / CommercialOpen-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.
Related Tool Categories
Frequently Asked Questions
Is syslog TCP or UDP 514?→
Syslog uses UDP 514 (RFC 5426). IANA assigns TCP 514 to the rsh shell service, and syslog over TLS uses TCP 6514 per RFC 5425.
Is syslog on port 514 encrypted?→
No. RFC 5426 says the UDP transport provides no strong sender authentication and recommends IPsec or other protection on unsecured networks; RFC 5425 defines syslog over TLS.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 514 is not guaranteed to be Syslog. Exploited-in-the-wild data from the CISA KEV catalog (CC0).