Rain Wiki · Linux

journalctl and the systemd journal

How to read logs with journalctl, check how much space the journal uses and shrink it safely with --vacuum options.

Linux · Rain Wiki

journalctl is the command that reads the systemd journal, the binary log store used by most modern Linux distributions. It filters messages by service, boot, time and priority, and it can also report and limit the journal's disk usage, which often grows to several gigabytes in /var/log/journal.

Reading logs

'journalctl -u nginx.service' shows the messages of one unit. '-b' limits output to the current boot, '-b -1' to the previous one. '-p err' shows only errors and worse. '--since "1 hour ago"' limits by time, and '-f' follows new messages live.

Disk usage

'journalctl --disk-usage' prints the total size of active and archived journal files.

'--vacuum-size=', '--vacuum-time=' and '--vacuum-files=' remove archived journal files until the limit is met; they do not touch the active files.

Permanent limits

Limits are set in /etc/systemd/journald.conf, for example SystemMaxUse=500M, then applied with 'systemctl restart systemd-journald'. Without a setting, journald by default keeps the journal within 10% of the file system size, capped at 4 GB.

How to shrink the journal

  1. Check the size: journalctl --disk-usage
  2. Rotate the active files so they can be vacuumed: sudo journalctl --rotate
  3. Keep only two weeks: sudo journalctl --vacuum-time=2weeks
  4. Or keep at most 500 MB: sudo journalctl --vacuum-size=500M
  5. To make it permanent, set SystemMaxUse=500M in /etc/systemd/journald.conf and run: sudo systemctl restart systemd-journald

Cautions

  • Vacuumed logs are gone; keep enough history to investigate problems.
  • Do not delete files in /var/log/journal by hand while journald runs.

Note: RainServer offers monitoring and safe cleanup for Linux servers; it shows what will change and asks first.

Sources

Last updated: 2026-10-08

Related articles