iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Use journalctl -n 50 to show the latest 50 system-journal entries, journalctl -f to watch new entries arrive, and journalctl -u nginx.service --since today to narrow logs to a service and time range. Add options together to investigate a specific issue; the examples below cover the most useful combinations.
Quick journalctl commands
| What you want | Command |
|---|---|
| Show the latest 10 entries | journalctl -n 10 |
| Show the latest 50 entries | journalctl -n 50 |
| Follow new entries as they arrive | journalctl -f |
| Show and follow a service | journalctl -u nginx.service -f |
| Show a service’s entries since today’s midnight | journalctl -u nginx.service --since today |
| Show entries from the last hour | journalctl --since '-1 hour' |
| Show entries from the current boot | journalctl -b |
| Show entries from the previous boot | journalctl -b -1 |
| Search message text for “timeout” | journalctl --grep='timeout' |
| Use ISO-style timestamps | journalctl -o short-iso |
| Inspect all structured fields for a service | journalctl -u nginx.service -o verbose |
These options are documented in the systemd 255 manual. Options can vary with the systemd version installed on a host, so check that machine’s local journalctl manual if an option is unavailable.
Tail recent entries or follow the live journal
Get a bounded snapshot
Use -n or --lines= to limit output to the newest entries. The documented default for this option is 10:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →journalctl -n 50
Watch new entries
Use -f or --follow to print recent entries and continue displaying new ones as they are appended:
#1 Best Overall
journalctl -f
For a fixed-size initial view before watching live activity, combine the options:
journalctl -n 50 -f
Follow mode implies a line limit. If you use --no-tail with follow, journalctl displays all stored output lines instead of starting with only the tail.
Filter logs by service, time, or message
Choose a systemd unit
Use -u UNIT or --unit=UNIT to select entries associated with a service or another systemd unit. For example, inspect recent entries for a service and then follow it while reproducing a current problem:
journalctl -u my-service.service --since '30 minutes ago'
journalctl -u my-service.service -f
Unit names depend on what is installed and configured on the host; nginx.service is only an example. The option accepts a unit name or pattern.
Set a time range
Use --since=TIME and --until=TIME to bound the entries. The manual describes these as selecting entries on or newer than the start and on or older than the end. Accepted forms include date-time strings, dates, relative times, and words such as today and yesterday.
journalctl --since '2026-10-09 09:00:00' --until '2026-10-09 10:00:00'
journalctl --since yesterday --until today
journalctl --since '-1 hour'
Quote relative-time phrases so the shell passes each phrase as one argument.
Search message text
-g PATTERN or --grep=PATTERN filters the MESSAGE= field using Perl-compatible regular expressions. By default, a pattern containing only lowercase letters is case-insensitive; a pattern containing uppercase letters is case-sensitive. The --case-sensitive option can override that behavior.
journalctl --grep='timeout'
journalctl -u my-service.service --grep='connection.*failed'
Match structured fields
Pass a structured field as FIELD=VALUE. Matches on different fields combine with AND, narrowing the results to entries that satisfy every field. Repeating a field matches either supplied value.
journalctl _PID=1234
journalctl _PID=1234 PRIORITY=3
journalctl _SYSTEMD_UNIT=nginx.service _PID=1234
Field names and values are case-sensitive. To discover the fields attached to an entry, use verbose output.
Rank #4
Select the current or a previous boot
Use -b or --boot to restrict entries to a boot. With no offset, -b selects the current boot; -b -1 selects the previous one. Add -k to select kernel messages, such as kernel entries from the prior boot:
journalctl -b
journalctl -b -1
journalctl -k -b -1
Choose an output format
| Format | Use it when |
|---|---|
short |
You want the default concise, one-entry-per-line display. |
short-iso |
You want ISO 8601 profile timestamps. |
short-iso-precise |
You need microsecond timestamp precision. |
verbose |
You need to inspect all structured fields for each entry. |
json |
You need newline-separated JSON objects for processing. |
cat |
You need message text without metadata such as timestamps. |
Set the format with -o FORMAT, for example journalctl -o short-iso. Because cat omits timestamps, it is a poor choice when you need to correlate events by time. Use --utc when you need timestamps expressed in Coordinated Universal Time.
Understand what journalctl can display
journalctl prints entries stored by systemd-journald and systemd-journal-remote. With no arguments, it displays accessible entries from the oldest collected entry onward. What you can see depends on your permissions and the host’s journal configuration.
Best Value
Resolve access or missing-log problems
- If the system journal is inaccessible, check whether your account has permission. Root and members of groups such as
systemd-journal,adm, orwheelcommonly have access under the documented defaults, but distribution policy may differ. journalctl --userworks only when persistent logging is enabled, according to the manual.- Do not start troubleshooting with
--quiet: it suppresses informational messages and certain warnings about inaccessible journals that may explain what is wrong.
Control paging and long lines
Output is sent through less by default. Add --no-pager when you do not want paging, such as in a script. In the pager, long lines may extend beyond the screen width; move left or right to inspect the hidden portion.
Check option support on the host
The examples here follow the systemd 255 journalctl manual. Since option availability can depend on the installed systemd version, consult the manual on the target Linux host before relying on an unfamiliar switch.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems

