Skip to content

journalctl Basics

Systemd Journalctl Basics
Systemd's journalctl is the primary utility for querying and managing logs generated by the journald service, which is the systemd component responsible for centralized logging. Unlike traditional syslog daemons, journald stores logs in a binary format, enabling efficient storage, structured data, and integration with systemd units. journalctl provides a powerful CLI interface to inspect, filter, and analyze these logs, making it essential for troubleshooting services, monitoring system events, and auditing system behavior.


Basic Usage and Syntax

The core syntax for journalctl is:

journalctl [OPTIONS...] [MATCHES...]
- --version: Display the version of journalctl.
- -x: Expand log lines with explanations (useful for parsing structured data).
- -b: Show logs from the current boot session.
- --list-boots: List all boot sessions (useful for multi-boot logs).

Example:

journalctl -x --since "1 hour ago"
This command retrieves logs from the last hour, expanding each line for clarity.


Filtering Logs

journalctl allows precise filtering using unit names, priorities, keywords, and time ranges.

  • By Unit:

    journalctl -u sshd.service
    
    Filters logs specific to the sshd.service unit.

  • By Priority:

    journalctl -p 3
    
    Shows only error (level 3) logs. Priorities range from 0 (emerg) to 7 (debug).

  • By Time Range:

    journalctl --since "2023-10-01 08:00:00" --until "2023-10-01 09:00:00"
    
    Restricts logs to a specific time window.

  • By Keywords:

    journalctl _COMM=crond
    
    Filters logs from the crond process.


Real-Time Monitoring

To monitor logs in real time:

journalctl -f
This follows the log output, similar to tail -f, and is ideal for observing service startups, crashes, or ongoing processes.

For continuous monitoring of a specific unit:

journalctl -u nginx.service -f


Managing Journal Storage

journald can be configured to limit disk usage via /etc/systemd/journald.conf. Key options include:
- SystemMaxUse: Maximum size of the journal (e.g., 100M).
- SystemKeepFree: Minimum free disk space (e.g., 1G).

To apply changes:

sudo systemctl restart journald.service

For manual log rotation or cleanup:

sudo journalctl --vacuum-time=1d  # Delete logs older than 1 day
sudo journalctl --vacuum-size=100M  # Delete logs until journal is 100M


Troubleshooting Tips

  • Missing Logs: Ensure journald is running (systemctl status journald).
  • No Pager: Use --no-pager to bypass the default pager for easier reading.
  • Large Logs: Use --output=json or --output=json-pretty for structured analysis.

Key takeaways

  • journalctl is the primary tool for interacting with systemd's journald logging system.
  • Logs are stored in a binary format, optimized for efficiency and structured data.
  • Use filters like -u, -p, --since, and --until to narrow down log searches.
  • Real-time monitoring with -f is invaluable for observing dynamic system behavior.
  • Configure journald to manage disk usage and automate log cleanup.