Skip to Content
DocsOperationsSystem AdministrationLogs & journalctl

Logs & journalctl

systemd-journald is the system logging service in Ubuntu 26.04. It collects and manages all logs from the kernel, services, and applications. journalctl is the command-line tool for querying and analyzing these logs.

journalctl Basics

Viewing Logs

# View all logs journalctl # View the latest logs (tail) journalctl -e # Follow new logs in real time (similar to tail -f) journalctl -f # View the most recent N entries journalctl -n 50 # Output without paging journalctl --no-pager # Reverse order (newest first) journalctl -r

Output Formats

# Short format (default) journalctl -o short # Verbose format (shows all fields) journalctl -o verbose # JSON format journalctl -o json # JSON format (one entry per line, convenient for scripting) journalctl -o json-lines # Message content only journalctl -o cat

Log Filtering

Filter by Service

# View logs for a specific service journalctl -u nginx.service # View logs for multiple services journalctl -u nginx.service -u php-fpm.service # Follow a specific service's logs in real time journalctl -u myapp.service -f

Filter by Time

# View logs from the current boot journalctl -b # View logs from the previous boot journalctl -b -1 # List all boot records journalctl --list-boots # Specify a time range journalctl --since "2026-03-24 10:00:00" journalctl --since "2026-03-24 10:00:00" --until "2026-03-24 12:00:00" # Use relative time journalctl --since "1 hour ago" journalctl --since "30 min ago" journalctl --since today journalctl --since yesterday --until today

Filter by Priority

Log priority levels range from 0 (most severe) to 7 (most verbose):

LevelNameDescription
0emergSystem is unusable
1alertImmediate action required
2critCritical error
3errError
4warningWarning
5noticeNormal but significant
6infoInformational
7debugDebug
# Show only errors and above journalctl -p err # Show only warnings journalctl -p warning # Show a range of priorities journalctl -p warning..err

Filter by Other Criteria

# By process PID journalctl _PID=1234 # By user ID journalctl _UID=1000 # By executable path journalctl _EXE=/usr/bin/python3 # Combine conditions journalctl _SYSTEMD_UNIT=nginx.service -p err --since today # Kernel logs journalctl -k journalctl --dmesg

Searching Log Content

# Filter with grep journalctl -u nginx.service | grep "error" # Use journalctl's built-in matching journalctl -g "failed|error|timeout"

Log Storage Configuration

Configuration File

The journald configuration file is located at /etc/systemd/journald.conf:

sudo nano /etc/systemd/journald.conf

Common configuration options:

[Journal] # Log storage mode: persistent (to disk), volatile (memory only), auto (default) Storage=persistent # Maximum disk space for logs SystemMaxUse=500M # Maximum size of a single log file SystemMaxFileSize=50M # Maximum retention time MaxRetentionSec=1month # Maximum memory usage for logs RuntimeMaxUse=100M # Log compression Compress=yes # Forward to syslog ForwardToSyslog=yes # Rate limiting: max 10000 entries per service per 30 seconds RateLimitIntervalSec=30s RateLimitBurst=10000

Apply configuration changes:

sudo systemctl restart systemd-journald

Ensuring Log Persistence

By default, if the /var/log/journal/ directory does not exist, logs are only kept in memory. To enable persistence:

# Create the persistent log directory sudo mkdir -p /var/log/journal sudo systemd-tmpfiles --create --prefix /var/log/journal # Or set it in the configuration file # Storage=persistent # Restart the service sudo systemctl restart systemd-journald

Log Rotation and Cleanup

Manual Cleanup

# Clean by time: keep only the last 7 days of logs sudo journalctl --vacuum-time=7d # Clean by size: keep only 500MB of logs sudo journalctl --vacuum-size=500M # Clean by file count: keep only the 5 most recent log files sudo journalctl --vacuum-files=5 # View current disk usage by logs journalctl --disk-usage

Verify Log Integrity

# Check log file consistency journalctl --verify

Relationship with syslog

systemd-journald can work alongside traditional syslog (such as rsyslog):

# Check if rsyslog is installed dpkg -l rsyslog # rsyslog log files are located under /var/log/ ls /var/log/syslog ls /var/log/auth.log ls /var/log/kern.log

Traditional Log Files

FileDescription
/var/log/syslogGeneral system log
/var/log/auth.logAuthentication log
/var/log/kern.logKernel log
/var/log/dpkg.logPackage installation log
/var/log/apt/history.logAPT operation history
/var/log/boot.logBoot log

Configuring rsyslog

# Main configuration file sudo nano /etc/rsyslog.conf # Custom rules go in this directory ls /etc/rsyslog.d/

rsyslog rule example (write nginx logs to a separate file):

# /etc/rsyslog.d/nginx.conf if $programname == 'nginx' then /var/log/nginx/syslog.log & stop

logrotate Log Rotation

logrotate manages rotation of traditional log files:

# Main configuration file cat /etc/logrotate.conf # Application configurations directory ls /etc/logrotate.d/

Custom logrotate configuration example:

sudo nano /etc/logrotate.d/myapp
/var/log/myapp/*.log { daily missingok rotate 14 compress delaycompress notifempty create 0640 myapp myapp sharedscripts postrotate systemctl reload myapp.service > /dev/null 2>&1 || true endscript }
# Test logrotate manually sudo logrotate -d /etc/logrotate.d/myapp # dry-run sudo logrotate -f /etc/logrotate.d/myapp # force execution

Practical Tips

Monitor Service Startup Failures

# Create a script to monitor failed services journalctl -p err -u "*.service" --since "5 min ago" --no-pager -o cat

Export Logs

# Export as a text file journalctl -u nginx.service --since today > /tmp/nginx-today.log # Export in binary format (readable by journalctl) journalctl -u nginx.service -o export > /tmp/nginx.export
journalctl -k | grep -i "i/o\|error\|disk\|sda"

Boot Process Analysis

# View logs from the boot process journalctl -b --no-pager | head -100
Last updated on