whatis journald
journald (journalctl)
Also known as: systemd journal, journalctl
systemd's logging service, which collects kernel, service, and application logs in a structured binary journal queried with journalctl.
What Is journald (journalctl) in Linux?
journald captures everything services write to stdout and stderr, plus syslog and kernel messages, and tags each entry with the unit, PID, priority, and boot. That makes filtering precise: one unit, one boot, errors only, or the last ten minutes.
By default the journal may be stored only in memory; creating /var/log/journal makes it persistent. Size limits are set in /etc/systemd/journald.conf.
Example
journalctl -u nginx --since "1 hour ago" -p err
journalctl -b -1 Learn more about journald (journalctl)
- journalctl and /var/log Explained Linux logs live in two places on most modern systems: the systemd journal, queried with journalctl, and traditional plain-text files under /var/log. This guide covers reading, filtering, and following logs in both.
- logrotate Explained: Keeping Log Files From Eating Your Disk logrotate renames, compresses, and eventually deletes aging log files on a schedule, and nearly every distro ships it preconfigured. Here is how the rotation cycle works and how to write configs for your own apps.
- lnav: Log Analysis Without grep Gymnastics A log viewer that parses timestamps, merges files into one timeline, and lets you query logs with SQL, which is what you actually wanted when you started piping grep into awk.
Related tools
- journalctl Query Builder Compose systemd journal queries with unit, boot, priority, time-range, and grep filters.