Logs are your record of what happened on a system, and they are the first place to look when something breaks or looks suspicious. Modern Linux distributions use two logging systems side by side: the systemd journal and rsyslog, with logrotate keeping file-based logs under control. Knowing which one holds what, and how to filter quickly, turns a long search into a one-line command. systemd-journald collects messages from the kernel, early boot, services' stdout and stderr, and the syslog interface, storing them in a structured binary journal with fields such as the unit, PID and priority. On many distributions the journal is kept only in memory under /run/log/journal unless /var/log/journal exists or Storage=persistent is set in /etc/systemd/journald.conf. Without persistence, logs from before the last reboot are gone. journalctl --disk-usage shows its size, journalctl --vacuum-size=500M or --vacuum-time=2weeks trims it, and SystemMaxUse= in journald.conf caps it.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.