How systemd logging works: journald and rsyslog
On modern Linux distributions (Ubuntu, Debian, CentOS, Rocky Linux, AlmaLinux), logs are collected by systemd-journald — a service that captures output from every unit file, the kernel, and system messages into a single binary journal. You can't read it directly, only through the journalctl utility. Some systems also use rsyslog, which pulls data from journald and writes it into text files such as /var/log/syslog or /var/log/messages.
Without a limit, the binary journal can silently grow to several gigabytes and fill up the disk. Let's cover reading logs, setting a size limit, and connecting journald with rsyslog.
Basic journalctl commands
Common ways to work with the journal:
journalctl -xe
journalctl -u nginx.service
journalctl -f
journalctl --since "1 hour ago"
journalctl -p err
journalctl --disk-usage
journalctl -xe shows the latest entries with error explanations, -u filters by a specific service, -f behaves like tail -f in real time, and --disk-usage shows how much disk space the journal takes up.
Limiting the size of the journald log
Storage settings live in /etc/systemd/journald.conf. The main parameters:
| Parameter | Purpose |
|---|---|
SystemMaxUse | maximum journal size on disk |
SystemKeepFree | amount of space kept free |
MaxRetentionSec | maximum retention period for entries |
Storage | storage mode: auto, persistent, volatile |
Example limiting the journal to 200 megabytes with a retention period of 14 days:
SystemMaxUse=200M
MaxRetentionSec=14day
After editing the configuration, restart the service:
systemctl restart systemd-journald
Check the current journal size with journalctl --disk-usage, and force cleanup of old entries with journalctl --vacuum-size=200M or journalctl --vacuum-time=14d.
Configuring rsyslog for text logs
rsyslog is useful when you need to view logs without journalctl — for example, for third-party parsing scripts. Its configuration lives in /etc/rsyslog.conf and the files in /etc/rsyslog.d/*.conf. A typical rule that sends messages from a specific service to a separate file:
if $programname == 'myapp' then /var/log/myapp.log
& stop
After changing the configuration, restart the service with systemctl restart rsyslog. Check that the syntax is correct with rsyslogd -N1.
Log rotation: journald and rsyslog
journald limits its own size using the parameters in journald.conf, but the text files written by rsyslog grow without limit unless an external tool handles them. That's the job of logrotate — it compresses and removes old files on a schedule. Detailed setup is covered in the article on logrotate on Linux. Without rotation, a file like /var/log/nginx/access.log can grow to tens of gigabytes in a month on a busy server.
What to do when the disk is full of logs
When disk space runs out specifically because of logs, find the culprit first:
journalctl --disk-usage
du -sh /var/log/* | sort -rh | head -10
Then either shrink the journal with journalctl --vacuum-size or set up rotation for a specific file. The general approach to finding what's taking up disk space is covered in the article on diagnosing a full disk.
Summary: a logging checklist
- View logs with
journalctl -u service_nameandjournalctl -f. - Limit the journal size in
/etc/systemd/journald.conf:SystemMaxUseandMaxRetentionSec. - Configure rsyslog rules in
/etc/rsyslog.d/for text logs. - Set up logrotate for the files written by rsyslog.
- Check
journalctl --disk-usageperiodically so the journal doesn't fill the disk.