Command library / journalctl
journalctl
Query the systemd journal (system and service logs)
Reads the systemd journal — the central, structured log almost every modern Linux service writes to. -u scopes it to one service, -b to the current boot, -f follows new lines live like tail -f, and -p filters by minimum severity.
Practice journalctlUsage
Options and flags
-u, --unitUNITonly logs from this systemd service (e.g. sshd.service)
-b, --bootonly logs since the current boot
-f, --followfollow the log live, like tail -f
-p, --priorityLEVELminimum severity: emerg, alert, crit, err, warning, notice, info, debug
-n, --linesNshow only the last N lines
Examples
journalctl -u sshd.serviceEvery logged event for the SSH daemon.
journalctl -u sshd.service -bSSH events since the machine last booted — rules out anything from before a restart.
journalctl -fWatch new log lines appear live — leave it running while you reproduce an issue.
journalctl -p errOnly error-level and worse, across every service — a fast first look at a sick system.
Common mistakes
Unit names normally need their full suffix — 'sshd' alone often matches nothing; 'sshd.service' is the actual systemd unit name.