Rain WikiWindows · Linux · Android

journalctl and the systemd journal

Command-line toolDistributions with systemdSafe to delete: Only with its own tool

journalctl is the command that reads the systemd journal, the binary log store used by most modern Linux distributions. It filters messages by service, boot, time and priority, and it can also report and limit the journal's disk usage, which often grows to several gigabytes in /var/log/journal.

1Reading logs

journalctl -u nginx.service shows the messages of one unit. -b limits output to the current boot, -b -1 to the previous one. -p err shows only errors and worse. '--since "1 hour ago"' limits by time, and -f follows new messages live.

2Disk usage

journalctl --disk-usage prints the total size of active and archived journal files.

--vacuum-size=, --vacuum-time= and --vacuum-files= remove archived journal files until the limit is met; they do not touch the active files.

3Permanent limits

Limits are set in /etc/systemd/journald.conf, for example SystemMaxUse=500M, then applied with systemctl restart systemd-journald. Without a setting, journald by default keeps the journal within 10% of the file system size, capped at 4 GB.

How to shrink the journal

  1. Check the size: journalctl --disk-usage
  2. Rotate the active files so they can be vacuumed: sudo journalctl --rotate
  3. Keep only two weeks: sudo journalctl --vacuum-time=2weeks
  4. Or keep at most 500 MB: sudo journalctl --vacuum-size=500M
  5. To make it permanent, set SystemMaxUse=500M in /etc/systemd/journald.conf and run: sudo systemctl restart systemd-journald

Cautions

  • Vacuumed logs are gone; keep enough history to investigate problems.
  • Do not delete files in /var/log/journal by hand while journald runs.

Sources

  1. journalctl(1) man7.org
  2. journald.conf(5) man7.org

Note: RainServer offers monitoring and safe cleanup for Linux servers; it shows what will change and asks first.

Last reviewed: