journalctl Basics
Systemd Journalctl Basics
Systemd's journalctl is the primary utility for querying and managing logs generated by the journald service, which is the systemd component responsible for centralized logging. Unlike traditional syslog daemons, journald stores logs in a binary format, enabling efficient storage, structured data, and integration with systemd units. journalctl provides a powerful CLI interface to inspect, filter, and analyze these logs, making it essential for troubleshooting services, monitoring system events, and auditing system behavior.
Basic Usage and Syntax¶
The core syntax for journalctl is:
--version: Display the version of journalctl.-
-x: Expand log lines with explanations (useful for parsing structured data).-
-b: Show logs from the current boot session.-
--list-boots: List all boot sessions (useful for multi-boot logs).
Example:
Filtering Logs¶
journalctl allows precise filtering using unit names, priorities, keywords, and time ranges.
-
By Unit:
Filters logs specific to the
sshd.serviceunit. -
By Priority:
Shows only error (level 3) logs. Priorities range from 0 (emerg) to 7 (debug).
-
By Time Range:
Restricts logs to a specific time window.
-
By Keywords:
Filters logs from the
crondprocess.
Real-Time Monitoring¶
To monitor logs in real time:
tail -f, and is ideal for observing service startups, crashes, or ongoing processes.
For continuous monitoring of a specific unit:
Managing Journal Storage¶
journald can be configured to limit disk usage via /etc/systemd/journald.conf. Key options include:
- SystemMaxUse: Maximum size of the journal (e.g., 100M).
- SystemKeepFree: Minimum free disk space (e.g., 1G).
To apply changes:
For manual log rotation or cleanup:
sudo journalctl --vacuum-time=1d # Delete logs older than 1 day
sudo journalctl --vacuum-size=100M # Delete logs until journal is 100M
Troubleshooting Tips¶
- Missing Logs: Ensure
journaldis running (systemctl status journald). - No Pager: Use
--no-pagerto bypass the default pager for easier reading. - Large Logs: Use
--output=jsonor--output=json-prettyfor structured analysis.
Key takeaways¶
journalctlis the primary tool for interacting with systemd'sjournaldlogging system.- Logs are stored in a binary format, optimized for efficiency and structured data.
- Use filters like
-u,-p,--since, and--untilto narrow down log searches. - Real-time monitoring with
-fis invaluable for observing dynamic system behavior. - Configure
journaldto manage disk usage and automate log cleanup.