# journald logs too big: check and limit the journal size

On many Linux servers the systemd journal slowly grows into the biggest thing in /var. You can see its size, trim it once, and set a limit so it stays small - all without touching other log files.

## 1. See how much space the journal uses

Run journalctl --disk-usage. It prints the total size of the archived and active journal files. The files normally live in /var/log/journal (persistent) or /run/log/journal (kept in memory only).
If the directory /var/log/journal does not exist, your system may keep the journal in memory only, and the size you see is limited by RAM, not by disk.

## 2. Trim it once

To keep the journal at or below a size, run sudo journalctl --vacuum-size=500M. To keep only recent entries, run sudo journalctl --vacuum-time=14d. Both remove old archived journal files; the logs they contained cannot be recovered afterwards.
Run journalctl --disk-usage again to confirm. Vacuuming removes whole archived files, so the result may be a little above or below the target.

## 3. Set a permanent limit

Open /etc/systemd/journald.conf (or create a drop-in file in /etc/systemd/journald.conf.d/) and set SystemMaxUse=500M under the [Journal] section. If you also want to keep some free space, SystemKeepFree=1G is another option. SystemMaxUse limits the persistent journal; RuntimeMaxUse does the same for the in-memory journal.
Apply it with sudo systemctl restart systemd-journald, then check journalctl --disk-usage after a while.

## 4. Decide what you need to keep

A smaller journal means a shorter history for debugging. If you need a longer history of one service, ship its logs to another place instead of keeping everything on the server.
Look at which service writes the most: journalctl -b -p warning --no-pager | tail shows recent warnings, and a service that logs thousands of lines per minute is worth fixing at the source.

## FAQ

**Is it safe to run journalctl --vacuum-size?**

Yes for the system itself: it only deletes old archived journal files. You lose that log history, so make sure you do not need it for an investigation first.

**Do I need to restart anything after editing journald.conf?**

Restart systemd-journald (sudo systemctl restart systemd-journald). The limit applies from then on and older files are trimmed as the journal rotates.

**Why is /var/log/journal missing?**

Persistent storage is off or set to auto without the directory. Then the journal lives under /run/log/journal in memory and is lost on reboot. Create /var/log/journal and restart journald only if you want persistence.

Source: https://raincleaner.eu/guides/journald-logs-too-big-limit-journal-size