On many Linux servers the systemd journal slowly grows into the biggest thing in /var. You can see its size, trim it once, and set a limit so it stays small - all without touching other log files.
Run journalctl --disk-usage. It prints the total size of the archived and active journal files. The files normally live in /var/log/journal (persistent) or /run/log/journal (kept in memory only).
If the directory /var/log/journal does not exist, your system may keep the journal in memory only, and the size you see is limited by RAM, not by disk.
To keep the journal at or below a size, run sudo journalctl --vacuum-size=500M. To keep only recent entries, run sudo journalctl --vacuum-time=14d. Both remove old archived journal files; the logs they contained cannot be recovered afterwards.
Run journalctl --disk-usage again to confirm. Vacuuming removes whole archived files, so the result may be a little above or below the target.
Open /etc/systemd/journald.conf (or create a drop-in file in /etc/systemd/journald.conf.d/) and set SystemMaxUse=500M under the [Journal] section. If you also want to keep some free space, SystemKeepFree=1G is another option. SystemMaxUse limits the persistent journal; RuntimeMaxUse does the same for the in-memory journal.
Apply it with sudo systemctl restart systemd-journald, then check journalctl --disk-usage after a while.
A smaller journal means a shorter history for debugging. If you need a longer history of one service, ship its logs to another place instead of keeping everything on the server.
Look at which service writes the most: journalctl -b -p warning --no-pager | tail shows recent warnings, and a service that logs thousands of lines per minute is worth fixing at the source.
Last updated: 2026-10-03
Yes for the system itself: it only deletes old archived journal files. You lose that log history, so make sure you do not need it for an investigation first.
Restart systemd-journald (sudo systemctl restart systemd-journald). The limit applies from then on and older files are trimmed as the journal rotates.
Persistent storage is off or set to auto without the directory. Then the journal lives under /run/log/journal in memory and is lost on reboot. Create /var/log/journal and restart journald only if you want persistence.
Built-in tools first, and what to check before you delete.
A practical order to check before you change anything.
A short, ordered checklist before you change anything.
Read the ID, understand it and search the maker's official page.
What each cleaner is built for, and who it fits.
What is safe to remove, and what needs a second look.
What it removes, what you lose, and when to use it.
Why it looks so big, and the safe ways to shrink it.
What it holds, what you lose, and the supported way to remove it.
What the cache is and how to clear it with Windows tools.
A sensible order for network, chipset, storage, graphics and more.
Add one driver or a whole folder from the command line.
Look first, back up, then remove - with Android's own tools.
Why they appear and how to remove them without losing a good shot.
Rain Cleaner: review before cleanup, free version, 14-day Pro trial.
Hash check, Defender scan and the SmartScreen steps.
How to report a security issue privately.
What we are working on now, next and later.
A safe order of checks: df, inodes, du, open deleted files, logs, packages and Docker.
Free, no account, no subscription. Windows 10 and 11.