UDP port 514 is mentioned just as an example. It is up to Splunk configuration to choose the port on which it is listening for data. Configure a port in Splunk and configure the same port in InTrust forwarding.
Forwarding happens exclusively over UDP. at the time of writing. Enhancement request TF00585145 has been submitted to Development to investigate the possibility of a TCP based mechanism in a future release of InTrust.