I just got an incoming connection to syslogd from 17.253.14.133 reported this morning.
To explain for the complainers: a firewall will allow incoming connections to the NAT-ed LAN, if there had been a prior outgoing connection. In ths case only, replies will be routed to the LAN-IP. In laymans terms, it means either syslogd or any other task had opened an outgoing connection to that internet-IP. As to why a local log daemon needs to communicate with the cloud is for Apple to answer.
If you care to run something like wireshark (or tcpdump) it would be plain visible how many connections are done to the apple cloud ervery second. It is not clear if all of these are actually needed, seems like every part has it's own (several!) cloud locations. And many of these (weather, stocks, news) cannot be turned off, and will happen even if you never ever open any of these. Yes, I did report that but I'm just one voice among millions.