journalctl and the systemd journal
journalctl is the command that reads the systemd journal, the binary log store used by most modern Linux distributions. It filters messages by service, boot, time and priority, and it can also report and limit the journal's disk usage, which often grows to several gigabytes in /var/log/journal.
1Reading logs
journalctl -u nginx.service shows the messages of one unit. -b limits output to the current boot, -b -1 to the previous one. -p err shows only errors and worse. '--since "1 hour ago"' limits by time, and -f follows new messages live.
2Disk usage
journalctl --disk-usage prints the total size of active and archived journal files.
--vacuum-size=, --vacuum-time= and --vacuum-files= remove archived journal files until the limit is met; they do not touch the active files.
3Permanent limits
Limits are set in /etc/systemd/journald.conf, for example SystemMaxUse=500M, then applied with systemctl restart systemd-journald. Without a setting, journald by default keeps the journal within 10% of the file system size, capped at 4 GB.
How to shrink the journal
- Check the size:
journalctl --disk-usage - Rotate the active files so they can be vacuumed:
sudo journalctl --rotate - Keep only two weeks:
sudo journalctl --vacuum-time=2weeks - Or keep at most 500 MB:
sudo journalctl --vacuum-size=500M - To make it permanent, set SystemMaxUse=500M in
/etc/systemd/journald.confand run:sudo systemctl restart systemd-journald
Cautions
- Vacuumed logs are gone; keep enough history to investigate problems.
- Do not delete files in
/var/log/journalby hand while journald runs.
Related articles
- logrotateWhat logrotate does, how its configuration in /etc/logrotate.conf and /etc/logrotate.d works, and how to test a rule safely.
- Disk usage with du and ncduHow to find what fills a Linux disk with du and the interactive ncdu, with options that stay on one file system.
- df (disk free)How to read df output, why Use% can reach 100% before Avail is zero for normal users, and how to check inodes with df -i.
Sources
- journalctl(1) man7.org
- journald.conf(5) man7.org
Note: RainServer offers monitoring and safe cleanup for Linux servers; it shows what will change and asks first.
Last reviewed: