Where are the logs on a Linux VPS: journalctl and /var/log

On a Linux VPS the logs live in two places: in the systemd journal, read with journalctl, and in files under /var/log. On Debian and Ubuntu nearly everything shows up in both; on AlmaLinux and Rocky too, with different file names. To find out why a service failed, start with journalctl -u service-name; for what a web server or application says, go to its own file.

journalctl, the commands you use most

I want to see… Command
The last lines of one service sudo journalctl -u nginx -n 50 --no-pager
Everything since the last boot sudo journalctl -b
Only errors sudo journalctl -p err -b
The last few minutes sudo journalctl --since "30 minutes ago"
Live, while you reproduce the problem sudo journalctl -u nginx -f (Ctrl+C to leave)
Kernel messages (disk, memory) sudo journalctl -k or sudo dmesg -T
How much space the journal takes journalctl --disk-usage

The files in /var/log

What Debian and Ubuntu AlmaLinux and Rocky
General system messages /var/log/syslog /var/log/messages
Logins and SSH /var/log/auth.log /var/log/secure
Web server /var/log/nginx/ or /var/log/apache2/ /var/log/nginx/ or /var/log/httpd/
Mail (Postfix) /var/log/mail.log /var/log/maillog
Package installs /var/log/apt/ and /var/log/dpkg.log /var/log/dnf.log
Certificates (certbot) /var/log/letsencrypt/ the same

To read a big file without opening all of it: sudo tail -n 100 /var/log/nginx/error.log for the end, sudo tail -f ... to follow live, and sudo grep -i error /var/log/syslog | tail to filter. Old files appear as .1 or .gz; zgrep reads the compressed ones.

Logs do not grow forever (and should not)

The logrotate program rotates the files in /var/log: it renames the current one, compresses it and deletes the oldest, following the rules in /etc/logrotate.d/. Your own applications only join that scheme if you write a rule for them. The systemd journal has a limit of its own, and you can shrink it by hand with sudo journalctl --vacuum-size=200M (the value is an example). Logs nobody rotates are the classic reason for a full disk: what fills the disk.

The journal can vanish on a reboot. On some systems the journal is kept in memory only and disappears when the server restarts, exactly when you needed it most. If /var/log/journal does not exist, the journal is not persistent; the setting is in /etc/systemd/journald.conf (option Storage=persistent). Depending on your system, check the distribution’s documentation.
Logs hold other people’s data. IP addresses and user names of the people visiting your site live here. Do not publish them or send them to anyone who does not need them; if you ask for help, cut what is personal. See personal data protection.
When asking for help, paste the 20 or 30 lines around the error, not the whole file nor a cropped screenshot. It is what lets the reader work out the cause.

Need us to confirm something on our side, such as the network, the machine or the console, while you read the logs? Write to us.

Open a support ticket

SEE ALSO

A service will not start: reading systemctl status

No space left on device: what fills the disk

Cron does not run: the usual causes

Common VPS and Cloud errors

RECOMMENDED PRODUCT

VPS server with root access

Resources of your own, the OS you choose, reinstall whenever you like. from $8.40/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?