Port 514: Syslog

Sending log messages to a central log server. Unauthenticated: anyone who can reach it can write fake logs. Keep it on a private network.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Examples:

Ports

1 of 41

Port Lookup

Port 514 at a glance

Port514
ProtocolUDP
ServiceSyslog
Open to the Internet?No, keep it on a private network
See What Is Listeningss -lntup | grep ':514 '
Test From Outsidenmap -sU -p 514 your-server
Block with UFWufw deny 514/udp
Block with nftablesnft add rule inet filter input udp dport 514 drop

Syslog uses UDP port 514. Sending log messages to a central log server.

Unauthenticated: anyone who can reach it can write fake logs. Keep it on a private network.

If ss shows something listening on port 514 on a public address, bind it to 127.0.0.1 or a private interface in the service's own configuration, and drop the port in the firewall as well.

Questions

What is port 514 used for?
Syslog. Sending log messages to a central log server.
Is it safe to open port 514?
No, keep it on a private network. Unauthenticated: anyone who can reach it can write fake logs. Keep it on a private network.
How do I check if port 514 is open?
On the server, ss -lntup | grep ':514 ' shows what is listening. From another machine, nmap -sU -p 514 your-server shows whether the firewall lets it through.
How do I block port 514?
With UFW: ufw deny 514/udp. With nftables, add a drop rule for dport 514 in your input chain.

Abuse from open ports on your VMs?

Frabs spots amplification, scans and floods leaving any VM and stops them, without touching your firewall.