journalctl Common Commands
Basic Viewing
| Command | Description |
|---|---|
journalctl | View all logs |
journalctl -e | Jump to the end of logs |
journalctl -f | Follow new log entries in real time |
journalctl -n 50 | View the last 50 log entries |
journalctl --no-pager | Output without paging |
Filter by Time
| Command | Description |
|---|---|
journalctl -b | Logs since current boot |
journalctl -b -1 | Logs from previous boot |
journalctl --since "2026-03-24 10:00:00" | Specify start time |
journalctl --since "2026-03-24" --until "2026-03-25" | Specify time range |
journalctl --since "1 hour ago" | Last 1 hour |
journalctl --since "30 min ago" | Last 30 minutes |
journalctl --since yesterday | Since yesterday |
journalctl --since today | Since today |
Filter by Service
| Command | Description |
|---|---|
journalctl -u nginx | View logs for a specific service |
journalctl -u nginx -u php-fpm | View logs for multiple services |
journalctl -u service-name -f | Follow a specific service in real time |
Filter by Priority
| Level | Number | Description |
|---|---|---|
| emerg | 0 | System unusable |
| alert | 1 | Immediate action required |
| crit | 2 | Critical error |
| err | 3 | General error |
| warning | 4 | Warning |
| notice | 5 | Notice |
| info | 6 | Informational |
| debug | 7 | Debug |
| Command | Description |
|---|---|
journalctl -p err | Show errors and above only |
journalctl -p warning | Show warnings and above only |
journalctl -p err..crit | Specify priority range |
Filter by Process/User
| Command | Description |
|---|---|
journalctl _PID=1234 | Filter by PID |
journalctl /usr/sbin/nginx | Filter by executable path |
journalctl _UID=1000 | Filter by user ID |
journalctl _COMM=sshd | Filter by process name |
Kernel Logs
| Command | Description |
|---|---|
journalctl -k | Show kernel messages only (similar to dmesg) |
journalctl -k -b | Kernel logs from current boot |
Output Formats
| Command | Description |
|---|---|
journalctl -o json-pretty | JSON format |
journalctl -o short | Short format |
journalctl -o verbose | Verbose format (all fields) |
journalctl -o cat | Message content only |
journalctl -u nginx --since today > /tmp/nginx-log.txt | Export to file |
Disk Space Management
| Command | Description |
|---|---|
journalctl --disk-usage | Check log disk usage |
sudo journalctl --vacuum-time=7d | Retain only 7 days of logs |
sudo journalctl --vacuum-size=500M | Limit logs to 500MB |
sudo journalctl --vacuum-files=5 | Limit to 5 log files |
Permanent configuration: edit /etc/systemd/journald.conf, set SystemMaxUse=500M, SystemMaxFileSize=50M, MaxRetentionSec=1month, then run sudo systemctl restart systemd-journald.
View Boot Records
| Command | Description |
|---|---|
journalctl --list-boots | List all boot records |
journalctl -b -1 | View previous boot logs |
journalctl -b -2 | View logs from two boots ago |
Practical Examples
| Command | Description |
|---|---|
journalctl -u ssh --since today | grep "Failed" | Find today’s SSH login failures |
journalctl -b -p err --no-pager | View errors from current boot |
journalctl -u nginx --since "1 hour ago" --no-pager -o short-iso > /tmp/nginx.log | Export a service’s last hour of logs |
journalctl -f -u nginx -u php8.5-fpm -u mysql | Monitor multiple services in real time |
Last updated on