Skip to main content

systemd logs: journalctl, rsyslog, and size limits

VDS / VPS Servers · 29.09.2026

How systemd logging works: journald and rsyslog

On modern Linux distributions (Ubuntu, Debian, CentOS, Rocky Linux, AlmaLinux), logs are collected by systemd-journald — a service that captures output from every unit file, the kernel, and system messages into a single binary journal. You can't read it directly, only through the journalctl utility. Some systems also use rsyslog, which pulls data from journald and writes it into text files such as /var/log/syslog or /var/log/messages.

Without a limit, the binary journal can silently grow to several gigabytes and fill up the disk. Let's cover reading logs, setting a size limit, and connecting journald with rsyslog.

Basic journalctl commands

Common ways to work with the journal:

journalctl -xe
journalctl -u nginx.service
journalctl -f
journalctl --since "1 hour ago"
journalctl -p err
journalctl --disk-usage

journalctl -xe shows the latest entries with error explanations, -u filters by a specific service, -f behaves like tail -f in real time, and --disk-usage shows how much disk space the journal takes up.

Limiting the size of the journald log

Storage settings live in /etc/systemd/journald.conf. The main parameters:

ParameterPurpose
SystemMaxUsemaximum journal size on disk
SystemKeepFreeamount of space kept free
MaxRetentionSecmaximum retention period for entries
Storagestorage mode: auto, persistent, volatile

Example limiting the journal to 200 megabytes with a retention period of 14 days:

SystemMaxUse=200M
MaxRetentionSec=14day

After editing the configuration, restart the service:

systemctl restart systemd-journald

Check the current journal size with journalctl --disk-usage, and force cleanup of old entries with journalctl --vacuum-size=200M or journalctl --vacuum-time=14d.

Configuring rsyslog for text logs

rsyslog is useful when you need to view logs without journalctl — for example, for third-party parsing scripts. Its configuration lives in /etc/rsyslog.conf and the files in /etc/rsyslog.d/*.conf. A typical rule that sends messages from a specific service to a separate file:

if $programname == 'myapp' then /var/log/myapp.log
& stop

After changing the configuration, restart the service with systemctl restart rsyslog. Check that the syntax is correct with rsyslogd -N1.

Log rotation: journald and rsyslog

journald limits its own size using the parameters in journald.conf, but the text files written by rsyslog grow without limit unless an external tool handles them. That's the job of logrotate — it compresses and removes old files on a schedule. Detailed setup is covered in the article on logrotate on Linux. Without rotation, a file like /var/log/nginx/access.log can grow to tens of gigabytes in a month on a busy server.

What to do when the disk is full of logs

When disk space runs out specifically because of logs, find the culprit first:

journalctl --disk-usage
du -sh /var/log/* | sort -rh | head -10

Then either shrink the journal with journalctl --vacuum-size or set up rotation for a specific file. The general approach to finding what's taking up disk space is covered in the article on diagnosing a full disk.

Summary: a logging checklist

  • View logs with journalctl -u service_name and journalctl -f.
  • Limit the journal size in /etc/systemd/journald.conf: SystemMaxUse and MaxRetentionSec.
  • Configure rsyslog rules in /etc/rsyslog.d/ for text logs.
  • Set up logrotate for the files written by rsyslog.
  • Check journalctl --disk-usage periodically so the journal doesn't fill the disk.
← Back to Knowledge Base Ask Support