Logs and journalctl
Concepts
Why Logs Matter
When something goes wrong on a Linux system (— )a service crashes, a login fails, a disk fills up, the gpu caught fire and is now burning your house down…) the answer is almost always in the logs. Logs record what happened, when, and often why.
Linux has two logging systems that work together:
- systemd journal (
journalctl) — collects logs from all systemd services, the kernel, and system messages. Binary format, fast queries, structured data.
- Traditional log files (
/var/log/) — text files written by rsyslog or syslog-ng. Older but still widely used.
/var/log/ — Traditional Log Files
| File |
Content |
syslog |
General system messages (Ubuntu) |
messages |
General system messages (Debian, if configured) |
auth.log |
Authentication events (logins, sudo, SSH) |
kern.log |
Kernel messages |
dpkg.log |
Package installation/removal history |
apt/history.log |
APT command history |
apt/term.log |
APT terminal output |
boot.log |
Boot messages |
dmesg |
Kernel ring buffer (hardware, drivers) |
faillog |
Failed login attempts |
lastlog |
Last login for each user |
wtmp |
Login/logout history (binary, read with last) |
# View recent syslog entries
sudo tail -20 /var/log/syslog
# Follow syslog in real time
sudo tail -f /var/log/syslog
# Search for SSH events
sudo grep "sshd" /var/log/auth.log | tail -10
# View package install history
cat /var/log/dpkg.log | tail -20
Log Rotation
Log files grow continuously. logrotate automatically compresses and rotates old logs: