Journald Log Management: Querying, Filtering, and Persisting Logs
journald collects every service log into one structured store. journalctl filters are faster than grepping text files once you know the patterns. journald is the logging daemon that systemd ships with. It collects logs from all services, the kernel, and user processes into a single structured store, replacing the scattered text files in /var/log that traditional syslog used. After years of working with journald, I find it faster and more capable than grepping log files, once you know the query patterns. Here is how I use it for everyday log management. The Basic Query The journalctl command queries the journal. With no arguments, it dumps everything, which is too much. I always narrow with filters. The most common filters are by unit, time, and priority. # Logs for one service sudo journalctl -u nginx # Follow in real time sudo journalctl -u nginx -f # Current boot only sudo journalctl -b # Previous boot sudo journalctl -b -1 The -b filter is one I use constantly. Most incidents are within the current boot, so filtering to the current boot removes days of irrelevant history instantly. For a crash that happened before a…