Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Use journalctl -n 50 to show the latest 50 system-journal entries, journalctl -f to watch new entries arrive, and journalctl -u nginx.service --since today to narrow logs to a service and time range. Add options together to investigate a specific issue; the examples below cover the most useful combinations.

Quick journalctl commands

What you want Command
Show the latest 10 entries journalctl -n 10
Show the latest 50 entries journalctl -n 50
Follow new entries as they arrive journalctl -f
Show and follow a service journalctl -u nginx.service -f
Show a service’s entries since today’s midnight journalctl -u nginx.service --since today
Show entries from the last hour journalctl --since '-1 hour'
Show entries from the current boot journalctl -b
Show entries from the previous boot journalctl -b -1
Search message text for “timeout” journalctl --grep='timeout'
Use ISO-style timestamps journalctl -o short-iso
Inspect all structured fields for a service journalctl -u nginx.service -o verbose

These options are documented in the systemd 255 manual. Options can vary with the systemd version installed on a host, so check that machine’s local journalctl manual if an option is unavailable.

Tail recent entries or follow the live journal

Get a bounded snapshot

Use -n or --lines= to limit output to the newest entries. The documented default for this option is 10:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
journalctl -n 50

Watch new entries

Use -f or --follow to print recent entries and continue displaying new ones as they are appended:

journalctl -f

For a fixed-size initial view before watching live activity, combine the options:

journalctl -n 50 -f

Follow mode implies a line limit. If you use --no-tail with follow, journalctl displays all stored output lines instead of starting with only the tail.

Filter logs by service, time, or message

Choose a systemd unit

Use -u UNIT or --unit=UNIT to select entries associated with a service or another systemd unit. For example, inspect recent entries for a service and then follow it while reproducing a current problem:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
journalctl -u my-service.service --since '30 minutes ago'
journalctl -u my-service.service -f

Unit names depend on what is installed and configured on the host; nginx.service is only an example. The option accepts a unit name or pattern.

Set a time range

Use --since=TIME and --until=TIME to bound the entries. The manual describes these as selecting entries on or newer than the start and on or older than the end. Accepted forms include date-time strings, dates, relative times, and words such as today and yesterday.

journalctl --since '2026-10-09 09:00:00' --until '2026-10-09 10:00:00'
journalctl --since yesterday --until today
journalctl --since '-1 hour'

Quote relative-time phrases so the shell passes each phrase as one argument.

Search message text

-g PATTERN or --grep=PATTERN filters the MESSAGE= field using Perl-compatible regular expressions. By default, a pattern containing only lowercase letters is case-insensitive; a pattern containing uppercase letters is case-sensitive. The --case-sensitive option can override that behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
journalctl --grep='timeout'
journalctl -u my-service.service --grep='connection.*failed'

Match structured fields

Pass a structured field as FIELD=VALUE. Matches on different fields combine with AND, narrowing the results to entries that satisfy every field. Repeating a field matches either supplied value.

journalctl _PID=1234
journalctl _PID=1234 PRIORITY=3
journalctl _SYSTEMD_UNIT=nginx.service _PID=1234

Field names and values are case-sensitive. To discover the fields attached to an entry, use verbose output.

Select the current or a previous boot

Use -b or --boot to restrict entries to a boot. With no offset, -b selects the current boot; -b -1 selects the previous one. Add -k to select kernel messages, such as kernel entries from the prior boot:

journalctl -b
journalctl -b -1
journalctl -k -b -1

Choose an output format

Format Use it when
short You want the default concise, one-entry-per-line display.
short-iso You want ISO 8601 profile timestamps.
short-iso-precise You need microsecond timestamp precision.
verbose You need to inspect all structured fields for each entry.
json You need newline-separated JSON objects for processing.
cat You need message text without metadata such as timestamps.

Set the format with -o FORMAT, for example journalctl -o short-iso. Because cat omits timestamps, it is a poor choice when you need to correlate events by time. Use --utc when you need timestamps expressed in Coordinated Universal Time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Understand what journalctl can display

journalctl prints entries stored by systemd-journald and systemd-journal-remote. With no arguments, it displays accessible entries from the oldest collected entry onward. What you can see depends on your permissions and the host’s journal configuration.

Resolve access or missing-log problems

  • If the system journal is inaccessible, check whether your account has permission. Root and members of groups such as systemd-journal, adm, or wheel commonly have access under the documented defaults, but distribution policy may differ.
  • journalctl --user works only when persistent logging is enabled, according to the manual.
  • Do not start troubleshooting with --quiet: it suppresses informational messages and certain warnings about inaccessible journals that may explain what is wrong.

Control paging and long lines

Output is sent through less by default. Add --no-pager when you do not want paging, such as in a script. In the pager, long lines may extend beyond the screen width; move left or right to inspect the hidden portion.

Check option support on the host

The examples here follow the systemd 255 journalctl manual. Since option availability can depend on the installed systemd version, consult the manual on the target Linux host before relying on an unfamiliar switch.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.