Skip to content

journalctl: filters and follow

Systemd’s journal is the first place to look when a service crashes or a node starts burning CPU. journalctl does far more than dump the entire log in sequence: it can filter by units, priorities, time windows, and stream in real time. Below is the working set I use daily.

Follow in real time

Behavior similar to tail -f, but aware of journald’s structured format:

journalctl -f

The -f flag (short for --follow) streams new entries as they appear. By default it shows all units — handy when you don’t know where the fire is.

Tip

Add --no-pager so output isn’t intercepted by less and doesn’t block the terminal in scripts and CI.

journalctl -f --no-pager

Filter by unit

The unit is the most common filter. One -u key and the specific service name:

journalctl -u nginx.service
journalctl -u docker.service

Multiple units can be passed — journalctl will show entries from all specified ones:

journalctl -u nginx.service -u postgresql.service
Note

The unit name must include the .service suffix. Omitting it may result in no matches or unexpected output from journalctl.

Priority and time filters

Priority filtering is set via -p (or --priority). Levels range from 0 to 7:

PriorityValue
0emerg
1alert
2crit
3err
4warning
5notice
6info
7debug

Show only errors and critical:

journalctl -p err

Time windows use --since and --until. Both absolute dates and relative expressions are supported:

journalctl --since "1 hour ago"
journalctl --since today --until "2 hours ago"
journalctl --since "2025-01-15 08:00:00" --until "2025-01-15 12:00:00"
Warning

--since without --until shows from the specified moment to now. If both are specified — the window is closed. Check the date order, or you’ll get empty output.

Combining flags

In practice, filters are combined. A typical request: watch errors from a specific service over the last hour in real time:

journalctl -u nginx.service -p err --since "1 hour ago" -f --no-pager

Another common pattern — show the last N lines for a unit with a priority filter:

journalctl -u postgresql.service -p warning -n 100 --no-pager

Here -n 100 limits output to the last 100 entries.

Quick reference for everyday flags:

FlagPurpose
-u <unit>Filter by unit
-fFollow (new entries in real time)
-p <level>Minimum priority
--since <time>Start of time window
--until <time>End of time window
-n <count>Last N entries
--no-pagerWithout pager
Tip

If journalctl returns empty results without errors — check whether the service is inactive or failed. You can see the status via systemctl status <unit>. Also verify that journald hasn’t rotated the needed entries: journalctl --disk-usage shows how much space the journal occupies.