
On a Linux VPS the logs live in two places: in the systemd journal, read with journalctl, and in files under /var/log. On Debian and Ubuntu nearly everything shows up in both; on AlmaLinux and Rocky too, with different file names. To find out why a service failed, start with journalctl -u service-name; for what a web server or application says, go to its own file.
journalctl, the commands you use most
| I want to see… | Command |
| The last lines of one service | sudo journalctl -u nginx -n 50 --no-pager |
| Everything since the last boot | sudo journalctl -b |
| Only errors | sudo journalctl -p err -b |
| The last few minutes | sudo journalctl --since "30 minutes ago" |
| Live, while you reproduce the problem | sudo journalctl -u nginx -f (Ctrl+C to leave) |
| Kernel messages (disk, memory) | sudo journalctl -k or sudo dmesg -T |
| How much space the journal takes | journalctl --disk-usage |
The files in /var/log
| What | Debian and Ubuntu | AlmaLinux and Rocky |
| General system messages | /var/log/syslog | /var/log/messages |
| Logins and SSH | /var/log/auth.log | /var/log/secure |
| Web server | /var/log/nginx/ or /var/log/apache2/ | /var/log/nginx/ or /var/log/httpd/ |
| Mail (Postfix) | /var/log/mail.log | /var/log/maillog |
| Package installs | /var/log/apt/ and /var/log/dpkg.log | /var/log/dnf.log |
| Certificates (certbot) | /var/log/letsencrypt/ | the same |
To read a big file without opening all of it: sudo tail -n 100 /var/log/nginx/error.log for the end, sudo tail -f ... to follow live, and sudo grep -i error /var/log/syslog | tail to filter. Old files appear as .1 or .gz; zgrep reads the compressed ones.
Logs do not grow forever (and should not)
The logrotate program rotates the files in /var/log: it renames the current one, compresses it and deletes the oldest, following the rules in /etc/logrotate.d/. Your own applications only join that scheme if you write a rule for them. The systemd journal has a limit of its own, and you can shrink it by hand with sudo journalctl --vacuum-size=200M (the value is an example). Logs nobody rotates are the classic reason for a full disk: what fills the disk.
| The journal can vanish on a reboot. On some systems the journal is kept in memory only and disappears when the server restarts, exactly when you needed it most. If /var/log/journal does not exist, the journal is not persistent; the setting is in /etc/systemd/journald.conf (option Storage=persistent). Depending on your system, check the distribution’s documentation. |
| Logs hold other people’s data. IP addresses and user names of the people visiting your site live here. Do not publish them or send them to anyone who does not need them; if you ask for help, cut what is personal. See personal data protection. |
| When asking for help, paste the 20 or 30 lines around the error, not the whole file nor a cropped screenshot. It is what lets the reader work out the cause. |
|
Need us to confirm something on our side, such as the network, the machine or the console, while you read the logs? Write to us. Open a support ticket |
|
SEE ALSO A service will not start: reading systemctl status No space left on device: what fills the disk |
RECOMMENDED PRODUCT VPS server with root access Resources of your own, the OS you choose, reinstall whenever you like. from $8.40/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











