How to read logs with journalctl, check how much space the journal uses and shrink it safely with --vacuum options.
journalctl is the command that reads the systemd journal, the binary log store used by most modern Linux distributions. It filters messages by service, boot, time and priority, and it can also report and limit the journal's disk usage, which often grows to several gigabytes in /var/log/journal.
'journalctl -u nginx.service' shows the messages of one unit. '-b' limits output to the current boot, '-b -1' to the previous one. '-p err' shows only errors and worse. '--since "1 hour ago"' limits by time, and '-f' follows new messages live.
'journalctl --disk-usage' prints the total size of active and archived journal files.
'--vacuum-size=', '--vacuum-time=' and '--vacuum-files=' remove archived journal files until the limit is met; they do not touch the active files.
Limits are set in /etc/systemd/journald.conf, for example SystemMaxUse=500M, then applied with 'systemctl restart systemd-journald'. Without a setting, journald by default keeps the journal within 10% of the file system size, capped at 4 GB.
journalctl --disk-usagesudo journalctl --rotatesudo journalctl --vacuum-time=2weekssudo journalctl --vacuum-size=500M/etc/systemd/journald.conf and run: sudo systemctl restart systemd-journald/var/log/journal by hand while journald runs.Note: RainServer offers monitoring and safe cleanup for Linux servers; it shows what will change and asks first.
Last updated: 2026-10-08
What logrotate does, how its configuration in /etc/logrotate.conf and /etc/logrotate.d works, and how to test a rule safely.
How to find what fills a Linux disk with du and the interactive ncdu, with options that stay on one file system.
How to read df output, why Use% can reach 100% before Avail is zero for normal users, and how to check inodes with df -i.