Linux journalctl Command: Read systemd Logs
journalctl searches and reads system and service logs stored in the systemd journal. You can narrow the scope to recent errors of a specific unit or messages from the current boot.
What is the journalctl command?
When run without arguments, it shows accessible journal entries in chronological order. -u filters by service unit, -b by boot session, and -p by priority. Regular users can only view some system logs depending on their permissions.
Basic syntax
journalctl [options] [filters]
Installed implementations and options may vary depending on the distribution. Check the description for your current system with man journalctl.
Examples
Viewing errors of the current boot
Examine messages of error level or higher from the current boot.
journalctl -b -p err
Viewing service logs
Replace the service name with the actual unit name and read the most recent 100 lines.
journalctl -u sshd.service -n 100
Follow Service Logs
Displays each time a new log is output. Press Ctrl+C to exit.
journalctl -u sshd.service -f
Reading a Single Service Log Line
journalctl searches logs collected in the systemd journal based on conditions. Below shows the three most recent entries of a specific service without paging.
journalctl -u sshd.service -n 3 --no-pager
Example output format (time, host, message varies by system):
Sep 28 09:00:00 web01 sshd[1234]: Server listening on 0.0.0.0 port 22.
-u narrows the scope to a unit, and -n limits the number of entries. Logs from other users may not be visible due to permissions. When investigating a previous boot, use -b -1, but on systems where journals are not stored permanently, previous boot logs may be unavailable.
Narrow the time window with --since '2026-09-28 09:00' or --until. Account for the system time zone and inspect entries just before and after the event to distinguish a cause from follow-on errors. Logs may contain tokens or personal data, so redact sensitive values before sharing them.
Main Options and Format
| Options/Format | Description |
|---|---|
-u UNIT |
Limits to logs of the specified unit. |
-b |
Selects logs of the current boot. |
-n N |
Displays only the most recent N entries. |
-f |
Continuously outputs new logs. |
-p LEVEL |
Select messages with the specified importance level or higher. |
--since TIME |
Select logs after the specified time. |
Precautions when using
Logs may contain sensitive information such as user data, paths, and tokens, so check them before sharing. Previous boot logs may not be available if persistent journal storage is not enabled. Do not use --vacuum-* during simple viewing, as it removes stored logs.
Frequently Asked Questions
Why are previous boot logs not visible?
The journal may not be stored persistently or may have already been rotated or deleted. Check from the preserved boot sessions using journalctl --list-boots.
Official Documentation
You can check the exact behavior of options and implementation differences in the official journalctl documentation.









