Querying Logs
The journalctl utility is the primary tool for querying and analyzing logs managed by the systemd journal. It allows administrators to filter, search, and inspect logs from services, kernel events, and user sessions. This section covers techniques for querying and filtering logs effectively.
Basic Querying with journalctl¶
To retrieve logs, use journalctl with time-based filters or to follow real-time logs.
Example:
# Show logs from the last hour
journalctl --since "1 hour ago"
# Follow real-time logs (similar to 'tail -f')
journalctl -f
Use --until to limit logs to a specific time range:
Filtering by Unit, Service, or Process¶
Filter logs for a specific systemd unit (e.g., a service or target):
Filter by log level (e.g., error, warning):
Combine filters for precise results:
Advanced Filtering with journalctl Options¶
Use --grep to search for specific text in logs:
For more complex patterns, use --grep with regular expressions:
Filter by process ID (PID) or unit name using _PID or _SYSTEMD_UNIT:
Analyzing and Exporting Logs¶
Export logs to a file for analysis:
Use --output=json to extract structured data:
For advanced analysis, pipe logs to tools like jq for JSON processing:
Key takeaways¶
- Use
--sinceand--untilto narrow logs to specific time ranges. - Filter by unit, service, or log level to focus on relevant entries.
- Combine
--grepand regular expressions for precise text matching. - Export logs to files or use JSON output for structured analysis.
- Leverage
--rotateand log rotation settings to manage storage efficiently.