journalctl -u nginx -b -p err

journalctl Query Builder

Pick a unit, boot, priority, and time window, then copy a journalctl command that shows exactly the logs you need.

Service name, e.g. nginx or sshd. Leave empty for all units.
e.g. "1 hour ago", "yesterday", "2026-08-18 06:00"
Same formats as since. Leave empty for now.
PCRE pattern matched against the message text (systemd 249+).
journalctl -b

Priority reminder

Priorities follow syslog levels: 0 emerg, 1 alert, 2 crit, 3 err, 4 warning, 5 notice, 6 info, 7 debug. Selecting a level includes everything more severe, so -p warning shows warnings, errors, critical, alert, and emergency entries.

systemd journal query helper

This journalctl command generator covers the flags that answer most real questions about a Linux system: what did this service log during the last boot, what errors happened in the past hour, and what is it logging right now. Combine unit, boot, priority, and time filters instead of paging through the full journal.

journalctl FAQ

Why does journalctl show no entries for my unit?

Either the unit name is wrong (check with systemctl list-units), the logs are outside your boot or time filter, or your user lacks permission. Add yourself to the systemd-journal group or run with sudo to read system logs.

How do I see logs from before the last reboot?

Use -b -1 for the previous boot, or list all recorded boots with journalctl --list-boots. Persistent logging must be enabled (Storage=persistent in journald.conf) for logs to survive reboots on some distributions.

What is the difference between -g and piping to grep?

-g filters messages inside journalctl using PCRE before output formatting, which keeps colors and works with the pager. Piping to grep works everywhere but loses journal metadata and highlighting.

How do I limit how much disk space the journal uses?

Set SystemMaxUse in /etc/systemd/journald.conf, or clean up on demand with journalctl --vacuum-size=500M or --vacuum-time=30d.