journalctl: filters and follow
Systemd’s journal is the first place to look when a service crashes or a node starts burning CPU. journalctl does far more than dump the entire log in sequence: it can filter by units, priorities, time windows, and stream in real time. Below is the working set I use daily.
Follow in real time
Behavior similar to tail -f, but aware of journald’s structured format:
The -f flag (short for --follow) streams new entries as they appear. By default it shows all units — handy when you don’t know where the fire is.
Add --no-pager so output isn’t intercepted by less and doesn’t block the terminal in scripts and CI.
Filter by unit
The unit is the most common filter. One -u key and the specific service name:
Multiple units can be passed — journalctl will show entries from all specified ones:
The unit name must include the .service suffix. Omitting it may result in no matches or unexpected output from journalctl.
Priority and time filters
Priority filtering is set via -p (or --priority). Levels range from 0 to 7:
| Priority | Value |
|---|---|
| 0 | emerg |
| 1 | alert |
| 2 | crit |
| 3 | err |
| 4 | warning |
| 5 | notice |
| 6 | info |
| 7 | debug |
Show only errors and critical:
Time windows use --since and --until. Both absolute dates and relative expressions are supported:
--since without --until shows from the specified moment to now. If both are specified — the window is closed. Check the date order, or you’ll get empty output.
Combining flags
In practice, filters are combined. A typical request: watch errors from a specific service over the last hour in real time:
Another common pattern — show the last N lines for a unit with a priority filter:
Here -n 100 limits output to the last 100 entries.
Quick reference for everyday flags:
| Flag | Purpose |
|---|---|
-u <unit> | Filter by unit |
-f | Follow (new entries in real time) |
-p <level> | Minimum priority |
--since <time> | Start of time window |
--until <time> | End of time window |
-n <count> | Last N entries |
--no-pager | Without pager |
If journalctl returns empty results without errors — check whether the service is inactive or failed. You can see the status via systemctl status <unit>. Also verify that journald hasn’t rotated the needed entries: journalctl --disk-usage shows how much space the journal occupies.