startup
init times
systemd-analyze blame
systemd-analyze plot > plot.svg
systemd-analyze dot | dot -Tsvg > dot.svg
journalctl
# restrict to current/previous boot
journalctl -b
journalctl -b -1
journalctl --list-boots
filter
# also: `yesterday`, `today`, `tomorrow`, `now`
# relative by prepending `+` or `-` or `ago` in a sentence
journalctl --since "2015-01-10" --until "2015-01-11 03:00"
journalctl --since 09:00 --until "1 hour ago"
# unit, can include more than one
journalctl -u nginx.service
journalctl -u nginx.service -u php-fpm.service
# syslog identifier
journalctl -t snapshotbackup
# kernel messages
journalctl -k
# ids
journalctl _PID=666
journalctl _UID=1001
journalctl _GID=1001
# show all ids available
journalctl -F _UID
# priority
# 0: emerg, 1: alert, 2: crit, 3: err, 4: warning, 5: notice, 6: info, 7: debug
journalctl -p err
# truncate output to one line each entry
journalctl --no-full
# print all, include unprintable chars
journalctl -a
journalctl --no-pager
journalctl -o json
journalctl -o json-pretty
disk usage
# get disk usage of journal file
journalctl --disk-usage
configure in /etc/systemd/journald.conf:
MaxRetentionSec=1month
manually delete:
journalctl --vacuum-size=1G
journalctl --vacuum-time=1years
other
timedatectl status