journalctl - query the systemd journal
journalctl [options] [MATCHES...]
Options you will use
-u UNIT- Only this unit.
-f, --follow- Follow new entries. Ctrl+C to stop.
-n N, --lines=N- Last N lines (default 10).
-r, --reverse- Newest first.
-e- Jump to the end of the pager.
-p PRIO- Priority 0 emerg 1 alert 2 crit 3 err 4 warning 5 notice 6 info 7 debug. -p err means 0..3.
-b [ID|-N]- This boot; -b -1 the previous one. --list-boots lists them.
-k, --dmesg- Kernel messages only.
-x, --catalog- Add the catalog explanation text to known messages.
-g PATTERN, --grep- Only entries whose message matches.
-t IDENT- Only this syslog identifier.
-o FORMAT- short (default), short-iso, cat, json, json-pretty, verbose.
--since / --until- Time window: "2026-09-22 10:00", "1 hour ago", yesterday, today.
--disk-usage- How much disk the journal is using.
--vacuum-time=, --vacuum-size=- Prune old journal data.
--flush- Move /run journal data to /var/log/journal.
FIELD=VALUE- Match a journal field: _PID=, _SYSTEMD_UNIT=, _UID=.
--no-pager- Do not pipe the output into a pager.
--list-boots- List every boot the journal has, with its offset (0 = this one, -1 = the previous).
-S, --since DATE- Entries on or newer than this time: "2026-09-22 10:00", "1 hour ago", -1h, today, yesterday.
-U, --until DATE- Entries on or older than this time.
-o, --output FORMAT- short (default), short-iso, cat, json, json-pretty, verbose.
-t, --identifier ID- Only entries with this syslog identifier (the name before the PID in the log line).
-u, --unit UNIT- Only this unit (and the messages systemd writes about it).
-p, --priority PRIO- Only this priority and more severe: emerg alert crit err warning notice info debug (or 0-7).
-n, --lines N- Show the last N lines.
-b, --boot [ID|-N]- Only this boot; -b -1 the previous one.
Examples
$ journalctl -u demo -ftail one unit live
$ journalctl -p err -berrors and worse from this boot
$ journalctl -k | grep -i oomdid the OOM killer fire
$ journalctl -u kubelet --since "10 min ago"recent history of one unit
Gotchas
- If /var/log/journal does not exist the journal is VOLATILE - everything is lost at reboot and journalctl -b -1 finds nothing.
sudo mkdir -p /var/log/journal && sudo systemctl restart systemd-journaldmakes it persistent.
Taught in
- 2.32 journalctl as a query language
- 3.10 Sessions, SIGHUP, and surviving a disconnect
- 5.7 The OOM killer
- 18.1 Under kubectl: the nodes are Linux machines
- 18.3 Static pods: how the control plane runs itself
- 18.6 kubeadm init and join: what they actually do
- 20.3 The JDK tools, and who may attach
- 20.8 Native memory tracking: where the rest of the RSS goes
Try journalctl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.