# journalctl: filters and follow

LLMS index: [llms.txt](/en/llms.txt)

---

Systemd's journal is the first place to look when a service crashes or a node starts burning CPU. `journalctl` does far more than dump the entire log in sequence: it can filter by units, priorities, time windows, and stream in real time. Below is the working set I use daily.

## Follow in real time

Behavior similar to `tail -f`, but aware of journald's structured format:

```bash
journalctl -f
```

The `-f` flag (short for `--follow`) streams new entries as they appear. By default it shows all units — handy when you don't know where the fire is.

> [!TIP]
> Add `--no-pager` so output isn't intercepted by `less` and doesn't block the terminal in scripts and CI.

```bash
journalctl -f --no-pager
```

## Filter by unit

The unit is the most common filter. One `-u` key and the specific service name:

```bash
journalctl -u nginx.service
journalctl -u docker.service
```

Multiple units can be passed — journalctl will show entries from all specified ones:

```bash
journalctl -u nginx.service -u postgresql.service
```

> [!NOTE]
> The unit name must include the `.service` suffix. Omitting it may result in no matches or unexpected output from journalctl.

## Priority and time filters

Priority filtering is set via `-p` (or `--priority`). Levels range from 0 to 7:

| Priority | Value |
|-----------|----------|
| 0 | emerg |
| 1 | alert |
| 2 | crit |
| 3 | err |
| 4 | warning |
| 5 | notice |
| 6 | info |
| 7 | debug |

Show only errors and critical:

```bash
journalctl -p err
```

Time windows use `--since` and `--until`. Both absolute dates and relative expressions are supported:

```bash
journalctl --since "1 hour ago"
journalctl --since today --until "2 hours ago"
journalctl --since "2025-01-15 08:00:00" --until "2025-01-15 12:00:00"
```

> [!WARNING]
> `--since` without `--until` shows from the specified moment to now. If both are specified — the window is closed. Check the date order, or you'll get empty output.

## Combining flags

In practice, filters are combined. A typical request: watch errors from a specific service over the last hour in real time:

```bash
journalctl -u nginx.service -p err --since "1 hour ago" -f --no-pager
```

Another common pattern — show the last N lines for a unit with a priority filter:

```bash
journalctl -u postgresql.service -p warning -n 100 --no-pager
```

Here `-n 100` limits output to the last 100 entries.

Quick reference for everyday flags:

| Flag | Purpose |
|------|------------|
| `-u <unit>` | Filter by unit |
| `-f` | Follow (new entries in real time) |
| `-p <level>` | Minimum priority |
| `--since <time>` | Start of time window |
| `--until <time>` | End of time window |
| `-n <count>` | Last N entries |
| `--no-pager` | Without pager |

> [!TIP]
> If journalctl returns empty results without errors — check whether the service is `inactive` or `failed`. You can see the status via `systemctl status <unit>`. Also verify that journald hasn't rotated the needed entries: `journalctl --disk-usage` shows how much space the journal occupies.
