# startup ## init times ```sh systemd-analyze blame systemd-analyze plot > plot.svg systemd-analyze dot | dot -Tsvg > dot.svg ``` # journalctl ```sh # restrict to current/previous boot journalctl -b journalctl -b -1 journalctl --list-boots ``` ## filter ```sh # also: `yesterday`, `today`, `tomorrow`, `now` # relative by prepending `+` or `-` or `ago` in a sentence journalctl --since "2015-01-10" --until "2015-01-11 03:00" journalctl --since 09:00 --until "1 hour ago" ``` ```sh # unit, can include more than one journalctl -u nginx.service journalctl -u nginx.service -u php-fpm.service # syslog identifier journalctl -t snapshotbackup # kernel messages journalctl -k ``` ```sh # ids journalctl _PID=666 journalctl _UID=1001 journalctl _GID=1001 # show all ids available journalctl -F _UID ``` ```sh # priority # 0: emerg, 1: alert, 2: crit, 3: err, 4: warning, 5: notice, 6: info, 7: debug journalctl -p err ``` ```sh # truncate output to one line each entry journalctl --no-full # print all, include unprintable chars journalctl -a journalctl --no-pager journalctl -o json journalctl -o json-pretty ``` ## disk usage ```sh # get disk usage of journal file journalctl --disk-usage ``` configure in `/etc/systemd/journald.conf`: ``` MaxRetentionSec=1month ``` manually delete: ```sh journalctl --vacuum-size=1G journalctl --vacuum-time=1years ``` # other ```sh timedatectl status ```