How do I read system logs with journalctl?
Basic log viewing
On most modern Linux servers, systemd collects logs in a journal that you read with journalctl. Running it alone shows everything, oldest first, which is usually too much to scan. Narrowing by service makes the output far easier to read.
Use sudo journalctl -u nginx to see logs for one unit. Add -f to watch new entries as they arrive, similar to tail -f. Press Ctrl+C to stop following.
- journalctl -u nginx --since '1 hour ago'
- journalctl -u myapp -f for live logs
- journalctl -p err to show only error-level messages
- journalctl -b to show logs since the last boot
Limit and search
The --since and --until flags accept absolute times like '2025-01-01 09:00' or relative values like '30 min ago'. Use -n 100 to show only the last 100 lines. Pipe the output into grep when you need to find a specific error string.
Journal size can grow over time. Check usage with journalctl --disk-usage. To cap it, set SystemMaxUse in /etc/systemd/journald.conf, then restart the journald service. If a service writes its own log files instead, check its config for the log path, since journalctl will not show those entries.
Common mistakes
- Reading the full journal without filtering, which buries the useful lines.
- Forgetting sudo, which can hide logs from some services.
- Assuming an app has logs in journalctl when it writes its own log files instead.
