Logs & log management
Where logs live, reading /var/log and the journal, searching logs, and rotating them with logrotate.
When something goes wrong on a Linux machine (a service won't start, a disk fills up, someone tries to brute-force SSH) the answer is almost always in the logs. In this lesson you'll learn where logs live, how to read and search them efficiently, how to write your own entries, and how logrotate stops logs from filling the disk.
Two logging systems#
Modern distributions run two logging systems side by side:
- The systemd journal (
journald) collects everything: kernel messages, service stdout/stderr and syslog messages. It stores them in a binary, indexed format, and you read it withjournalctl. - Text files in
/var/log/, written by rsyslog (which receives messages from the journal) or by applications directly (nginx, MySQL, apt).
Ubuntu and Debian servers typically have both. Fedora and recent Debian desktop installs may be journal-only (no rsyslog), so journalctl is the one tool that works everywhere.
Important files in /var/log#
Most of these are readable only by root or the adm group. Use sudo, or add yourself to adm:
Reading the journal#
You met journalctl in the systemd lesson. These are the options you'll use most:
Priorities, from most to least severe, are emerg, alert, crit, err, warning, notice, info and debug. -p err means "err and worse".
Persistence and size
If /var/log/journal/ exists, the journal survives reboots; otherwise it lives only in /run (RAM). Debian and Ubuntu create it by default; if journalctl -b -1 says there's no previous boot, create it with sudo mkdir -p /var/log/journal and run sudo systemctl restart systemd-journald. Control the size:
Or set a permanent limit in a drop-in file:
Searching text logs#
Logs are just text, so everything from the text-processing lessons applies. Let's work on a sample web server access log:
The 192.0.2.44 client is probing for common vulnerable paths, a very typical sight on any public server. Other useful moves:
For a whole directory of logs, sudo grep -r "Out of memory" /var/log/ is often the fastest first step. grep -i, -C 3 (show context) and -E with alternation ('error|fatal|panic') are your best friends.
Compressed and rotated logs#
Old logs are rotated and compressed: syslog, syslog.1, syslog.2.gz, syslog.3.gz... The z* tools read .gz files directly:
zless pages through compressed logs. For .xz files use xzcat and xzgrep, and for .zst files zstdcat.
Writing to the log: logger#
Your scripts and cron jobs can log to syslog/the journal with logger:
That's much better than scattering ad-hoc files around, because everything lands in one searchable place, with timestamps and priorities.
logrotate: keeping logs under control#
logrotate runs daily (from a systemd timer, or cron on older systems), renames logs, compresses old ones, and deletes the oldest. Global defaults are in /etc/logrotate.conf, and each package drops its own rules into /etc/logrotate.d/. Here's a typical rule for your own app:
You can try logrotate safely as a normal user with your own state file. Here we force a rotation on a test log:
To check a real config without changing anything, use debug mode: sudo logrotate -d /etc/logrotate.d/myapp. To force a rotation now, run sudo logrotate -f /etc/logrotate.d/myapp.
Centralised logging#
With more than a couple of servers, logging into each one to grep doesn't scale. Teams ship logs to a central system: rsyslog forwarding, Grafana Loki, the ELK/OpenSearch stack, or a cloud service (CloudWatch, Google Cloud Logging, Datadog). The concepts are the same (timestamps, priorities, fields), but the search is faster and covers every machine.
Common mistakes#
- Not checking the logs first. "It doesn't work" is usually explained in one line of
journalctl -u service -n 50. - Deleting big logs with
rmwhile the app runs. The space isn't freed (see the disks lesson). Truncate the log, or fix rotation. - Rotating without telling the app. It keeps writing to the renamed file. Use
postrotatewith a reload/HUP, orcopytruncate. - Logging secrets. Passwords, tokens and full card numbers in logs are a security incident waiting to happen.
- Unbounded journal or debug logging in production quietly filling the disk. Set
SystemMaxUse=and sensible log levels.
What's next#
You can now run and troubleshoot the system. Time to automate it: the Advanced section starts with bash scripting basics.
Check your understanding
Quick quiz
1.On Ubuntu, where do you look for SSH login attempts and sudo usage?
2.What does logrotate's
copytruncateoption do?3.Which command searches a gzip-compressed rotated log without unpacking it first?
Finished reading?
Mark this lesson complete to track your progress.