Port 514: Syslog
UDP port 514 is syslog, used to send log messages to a central server; TCP 514 is the old rsh remote shell.
What runs on port 514
Syslog servers collect log lines from routers, firewalls, servers and appliances over UDP 514, with no encryption or authentication in the classic form. TCP 514 was historically assigned to rsh, an insecure remote shell from BSD Unix that trusted the client's address instead of a password. rsh is effectively obsolete.
On a home network
Routers, NAS boxes and firewalls can send their logs to a syslog server on 514, and some NAS devices (Synology, for example) can act as that server. Most home devices send logs out rather than listen.
If port 514 is reachable from the internet
A syslog server reachable from the internet will accept fake log entries from anyone and can be flooded. An rsh service on TCP 514 is a serious finding, since it was designed with weak trust-based login. Neither should face the internet.
How to check whether it is open on your network
If you run a syslog receiver on a NAS or Pi, make sure no router rule forwards 514 to it. A port scan will show TCP 514 if rsh is somehow running.
To find out whether port 514 is open on something in your home, and whether the internet can reach it, the app scans your Wi-Fi from your phone and checks your public address from the outside. It says what it checked and what it could not. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.