journalctl
Read the logs of services and the system
What it does
systemd collects the logs of every service in one journal, and journalctl shows them. -u keeps one service, -n the last lines, and -f prints new entries as they come (quit with Ctrl+C).
Limiting by time is handy: --since "1 hour ago" for the last hour, -b since the last boot. Without sudo a regular user may not see the system logs, so the command usually runs with it.
Syntax
sudo journalctl -u <service> -n <count>
sudo journalctl -u <service> -f
sudo journalctl -u <service> --since "1 hour ago"Examples
Show the last 50 lines of the nginx service log
sudo journalctl -u nginx -n 50same as:
sudo journalctl -n 50 -u nginx,sudo journalctl -u nginx --lines 50,sudo journalctl -u nginx --lines=50journalctl— the systemd journal-u nginx— this service (unit) only-n 50— the last 50 lines
Follow the nginx log live
sudo journalctl -u nginx -fsame as:
sudo journalctl -f -u nginx,sudo journalctl -fu nginx,sudo journalctl -u nginx --followjournalctl— the systemd journal-u nginx— this service only-f— show new entries as they come; quit with Ctrl+C