<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Logs on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/logs/</link><description>Recent content in Logs on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 17 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/logs/index.xml" rel="self" type="application/rss+xml"/><item><title>journalctl: filters and follow</title><link>https://lead-devops.blackdevhub.online/en/posts/journalctl-filtry-i-follow/</link><pubDate>Thu, 17 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/journalctl-filtry-i-follow/</guid><description>&lt;p&gt;Systemd&amp;rsquo;s journal is the first place to look when a service crashes or a node starts burning CPU. &lt;code&gt;journalctl&lt;/code&gt; does far more than dump the entire log in sequence: it can filter by units, priorities, time windows, and stream in real time. Below is the working set I use daily.&lt;/p&gt;&#10;&lt;h2 id="follow-in-real-time"&gt;Follow in real time&#10;&lt;/h2&gt;&#10;&lt;p&gt;Behavior similar to &lt;code&gt;tail -f&lt;/code&gt;, but aware of journald&amp;rsquo;s structured format:&lt;/p&gt;</description></item></channel></rss>