Logs & journalctl
systemd-journald is the system logging service in Ubuntu 26.04. It collects and manages all logs from the kernel, services, and applications. journalctl is the command-line tool for querying and analyzing these logs.
journalctl Basics
Viewing Logs
# View all logs
journalctl
# View the latest logs (tail)
journalctl -e
# Follow new logs in real time (similar to tail -f)
journalctl -f
# View the most recent N entries
journalctl -n 50
# Output without paging
journalctl --no-pager
# Reverse order (newest first)
journalctl -rOutput Formats
# Short format (default)
journalctl -o short
# Verbose format (shows all fields)
journalctl -o verbose
# JSON format
journalctl -o json
# JSON format (one entry per line, convenient for scripting)
journalctl -o json-lines
# Message content only
journalctl -o catLog Filtering
Filter by Service
# View logs for a specific service
journalctl -u nginx.service
# View logs for multiple services
journalctl -u nginx.service -u php-fpm.service
# Follow a specific service's logs in real time
journalctl -u myapp.service -fFilter by Time
# View logs from the current boot
journalctl -b
# View logs from the previous boot
journalctl -b -1
# List all boot records
journalctl --list-boots
# Specify a time range
journalctl --since "2026-03-24 10:00:00"
journalctl --since "2026-03-24 10:00:00" --until "2026-03-24 12:00:00"
# Use relative time
journalctl --since "1 hour ago"
journalctl --since "30 min ago"
journalctl --since today
journalctl --since yesterday --until todayFilter by Priority
Log priority levels range from 0 (most severe) to 7 (most verbose):
| Level | Name | Description |
|---|---|---|
| 0 | emerg | System is unusable |
| 1 | alert | Immediate action required |
| 2 | crit | Critical error |
| 3 | err | Error |
| 4 | warning | Warning |
| 5 | notice | Normal but significant |
| 6 | info | Informational |
| 7 | debug | Debug |
# Show only errors and above
journalctl -p err
# Show only warnings
journalctl -p warning
# Show a range of priorities
journalctl -p warning..errFilter by Other Criteria
# By process PID
journalctl _PID=1234
# By user ID
journalctl _UID=1000
# By executable path
journalctl _EXE=/usr/bin/python3
# Combine conditions
journalctl _SYSTEMD_UNIT=nginx.service -p err --since today
# Kernel logs
journalctl -k
journalctl --dmesgSearching Log Content
# Filter with grep
journalctl -u nginx.service | grep "error"
# Use journalctl's built-in matching
journalctl -g "failed|error|timeout"Log Storage Configuration
Configuration File
The journald configuration file is located at /etc/systemd/journald.conf:
sudo nano /etc/systemd/journald.confCommon configuration options:
[Journal]
# Log storage mode: persistent (to disk), volatile (memory only), auto (default)
Storage=persistent
# Maximum disk space for logs
SystemMaxUse=500M
# Maximum size of a single log file
SystemMaxFileSize=50M
# Maximum retention time
MaxRetentionSec=1month
# Maximum memory usage for logs
RuntimeMaxUse=100M
# Log compression
Compress=yes
# Forward to syslog
ForwardToSyslog=yes
# Rate limiting: max 10000 entries per service per 30 seconds
RateLimitIntervalSec=30s
RateLimitBurst=10000Apply configuration changes:
sudo systemctl restart systemd-journaldEnsuring Log Persistence
By default, if the /var/log/journal/ directory does not exist, logs are only kept in memory. To enable persistence:
# Create the persistent log directory
sudo mkdir -p /var/log/journal
sudo systemd-tmpfiles --create --prefix /var/log/journal
# Or set it in the configuration file
# Storage=persistent
# Restart the service
sudo systemctl restart systemd-journaldLog Rotation and Cleanup
Manual Cleanup
# Clean by time: keep only the last 7 days of logs
sudo journalctl --vacuum-time=7d
# Clean by size: keep only 500MB of logs
sudo journalctl --vacuum-size=500M
# Clean by file count: keep only the 5 most recent log files
sudo journalctl --vacuum-files=5
# View current disk usage by logs
journalctl --disk-usageVerify Log Integrity
# Check log file consistency
journalctl --verifyRelationship with syslog
systemd-journald can work alongside traditional syslog (such as rsyslog):
# Check if rsyslog is installed
dpkg -l rsyslog
# rsyslog log files are located under /var/log/
ls /var/log/syslog
ls /var/log/auth.log
ls /var/log/kern.logTraditional Log Files
| File | Description |
|---|---|
/var/log/syslog | General system log |
/var/log/auth.log | Authentication log |
/var/log/kern.log | Kernel log |
/var/log/dpkg.log | Package installation log |
/var/log/apt/history.log | APT operation history |
/var/log/boot.log | Boot log |
Configuring rsyslog
# Main configuration file
sudo nano /etc/rsyslog.conf
# Custom rules go in this directory
ls /etc/rsyslog.d/rsyslog rule example (write nginx logs to a separate file):
# /etc/rsyslog.d/nginx.conf
if $programname == 'nginx' then /var/log/nginx/syslog.log
& stoplogrotate Log Rotation
logrotate manages rotation of traditional log files:
# Main configuration file
cat /etc/logrotate.conf
# Application configurations directory
ls /etc/logrotate.d/Custom logrotate configuration example:
sudo nano /etc/logrotate.d/myapp/var/log/myapp/*.log {
daily
missingok
rotate 14
compress
delaycompress
notifempty
create 0640 myapp myapp
sharedscripts
postrotate
systemctl reload myapp.service > /dev/null 2>&1 || true
endscript
}# Test logrotate manually
sudo logrotate -d /etc/logrotate.d/myapp # dry-run
sudo logrotate -f /etc/logrotate.d/myapp # force executionPractical Tips
Monitor Service Startup Failures
# Create a script to monitor failed services
journalctl -p err -u "*.service" --since "5 min ago" --no-pager -o catExport Logs
# Export as a text file
journalctl -u nginx.service --since today > /tmp/nginx-today.log
# Export in binary format (readable by journalctl)
journalctl -u nginx.service -o export > /tmp/nginx.exportView Disk I/O Related Logs
journalctl -k | grep -i "i/o\|error\|disk\|sda"Boot Process Analysis
# View logs from the boot process
journalctl -b --no-pager | head -100