Skip to Content

journalctl Common Commands

Basic Viewing

CommandDescription
journalctlView all logs
journalctl -eJump to the end of logs
journalctl -fFollow new log entries in real time
journalctl -n 50View the last 50 log entries
journalctl --no-pagerOutput without paging

Filter by Time

CommandDescription
journalctl -bLogs since current boot
journalctl -b -1Logs from previous boot
journalctl --since "2026-03-24 10:00:00"Specify start time
journalctl --since "2026-03-24" --until "2026-03-25"Specify time range
journalctl --since "1 hour ago"Last 1 hour
journalctl --since "30 min ago"Last 30 minutes
journalctl --since yesterdaySince yesterday
journalctl --since todaySince today

Filter by Service

CommandDescription
journalctl -u nginxView logs for a specific service
journalctl -u nginx -u php-fpmView logs for multiple services
journalctl -u service-name -fFollow a specific service in real time

Filter by Priority

LevelNumberDescription
emerg0System unusable
alert1Immediate action required
crit2Critical error
err3General error
warning4Warning
notice5Notice
info6Informational
debug7Debug
CommandDescription
journalctl -p errShow errors and above only
journalctl -p warningShow warnings and above only
journalctl -p err..critSpecify priority range

Filter by Process/User

CommandDescription
journalctl _PID=1234Filter by PID
journalctl /usr/sbin/nginxFilter by executable path
journalctl _UID=1000Filter by user ID
journalctl _COMM=sshdFilter by process name

Kernel Logs

CommandDescription
journalctl -kShow kernel messages only (similar to dmesg)
journalctl -k -bKernel logs from current boot

Output Formats

CommandDescription
journalctl -o json-prettyJSON format
journalctl -o shortShort format
journalctl -o verboseVerbose format (all fields)
journalctl -o catMessage content only
journalctl -u nginx --since today > /tmp/nginx-log.txtExport to file

Disk Space Management

CommandDescription
journalctl --disk-usageCheck log disk usage
sudo journalctl --vacuum-time=7dRetain only 7 days of logs
sudo journalctl --vacuum-size=500MLimit logs to 500MB
sudo journalctl --vacuum-files=5Limit to 5 log files

Permanent configuration: edit /etc/systemd/journald.conf, set SystemMaxUse=500M, SystemMaxFileSize=50M, MaxRetentionSec=1month, then run sudo systemctl restart systemd-journald.

View Boot Records

CommandDescription
journalctl --list-bootsList all boot records
journalctl -b -1View previous boot logs
journalctl -b -2View logs from two boots ago

Practical Examples

CommandDescription
journalctl -u ssh --since today | grep "Failed"Find today’s SSH login failures
journalctl -b -p err --no-pagerView errors from current boot
journalctl -u nginx --since "1 hour ago" --no-pager -o short-iso > /tmp/nginx.logExport a service’s last hour of logs
journalctl -f -u nginx -u php8.5-fpm -u mysqlMonitor multiple services in real time
Last updated on