Logging & Journald
Keep your logs from disappearing when the journal is too small
🧩 The Challenge
Dealing with a service that crashed three hours ago only to realize the journal was so small it rolled over and purged the evidence is infuriating. I have spent way too many late nights looking at empty logs because of those default storage settings.
💡 The Fix
Increase the size of your persistent storage for systemd journald so you actually keep history for more than a few minutes. You just need to tweak one configuration line and make sure the directory exists.
mkdir -p /var/log/journal
echo "SystemMaxUse=1G" >> /etc/systemd/journald.conf
systemctl restart systemd-journald
⚙️ Why It Works
By creating that specific directory, you force journald to move from volatile RAM storage to persistent disk storage, while the config change sets a hard limit on how much space it can eat. It stops the silent data loss that happens by default on smaller cloud instances.
🚀 Pro-Tip: Run journalctl –disk-usage to see if your current setup is even hoarding enough data for your needs.
Linux Tips & Tricks | © ngelinux.com | 10/2/2026
