This guide explains how to find, read and retain system logs on Ubuntu and Debian. It also shows how to add traditional text log files on Debian and control how much disk space logs use.
These steps apply to standard BinaryLane images running Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12 or Debian 13.
Logging is already enabled on these images and persists across reboots. The main difference is where the logs are stored:
- Ubuntu uses the systemd journal and also writes traditional files such as
/var/log/syslogand/var/log/auth.log. - Debian uses the systemd journal by default. Traditional
auth.logandsyslogfiles are unavailable until you install rsyslog.
Before you start
Prerequisites:
- A VPS running one of the supported images listed above.
- Root access over SSH, or a user account with
sudoaccess.
The commands use sudo. If you are logged in as root, you can omit it.
Important: The operating system and its logging configuration are customer-managed. BinaryLane CIS hardened images use different logging settings. See What are CIS Hardened Images? if your server uses a hardened image.
TABLE OF CONTENTS
- Before you start
- See what your server is already logging
- Read logs with journalctl
- Install rsyslog on Debian for text log files
- Check that the journal survives a reboot
- Control how much disk space logs use
- Troubleshooting
- Things to know
- Related articles
1. See what your server is already logging
Check which logging services are running:
systemctl is-active systemd-journald rsyslog
On Ubuntu, the expected output is:
active active
On Debian, the expected output is:
active inactive
systemd-journald manages the systemd journal, where services and the kernel record events. rsyslog writes traditional text log files. Standard Debian 12 and Debian 13 images do not include rsyslog, so it reports inactive.
List the available log files:
ls /var/log
On Ubuntu, the list includes traditional logs such as:
alternatives.log apt auth.log btmp cloud-init.log dpkg.log journal kern.log lastlog syslog unattended-upgrades wtmp ...
On Debian, auth.log, kern.log and syslog are absent by default:
btmp cloud-init-output.log cloud-init.log journal lastlog wtmp ...
The relevant events are still available through the journal. The following table summarises the tested standard images:
| Logging feature | Ubuntu 24.04 | Ubuntu 26.04 | Debian 12 | Debian 13 |
|---|---|---|---|---|
| Persistent systemd journal | Yes | Yes | Yes | Yes |
| rsyslog text files | Installed | Installed | Not installed | Not installed |
| logrotate | Installed | Installed | Not installed | Not installed |
last and lastb | Installed | Not installed | Installed | Not installed |
2. Read logs with journalctl
journalctl works on all four supported images. Display the 50 most recent entries:
sudo journalctl -n 50
Common searches include:
| What you want to see | Command |
|---|---|
| One service's logs | sudo journalctl -u ssh |
| Entries from the last hour | sudo journalctl --since "1 hour ago" |
| A specific time window | sudo journalctl --since "2026-10-01 12:00" --until "2026-10-01 13:00" |
| Errors since the current boot | sudo journalctl -b -p err |
| Kernel messages | sudo journalctl -k |
| The previous boot | sudo journalctl -b -1 |
| New entries as they arrive | sudo journalctl -f - press Ctrl+C to stop |
The OpenSSH service is named ssh on these Ubuntu and Debian images. Times are shown in the server's configured time zone. Check it with:
timedatectl
Find successful and failed SSH logins
sudo journalctl -u ssh --since "today" | grep -E 'Accepted|Failed|Invalid'
Example output:
Oct 01 12:19:04 my-server sshd[1059]: Invalid user baduser from 198.51.100.77 port 4764 Oct 01 12:19:05 my-server sshd[1061]: Accepted publickey for root from 192.0.2.50 port 4766 ssh2: ED25519 SHA256:...
Accepted records a successful login. Invalid user and Failed password record failed attempts. Internet-facing servers commonly receive unsuccessful login attempts. See How to install and use fail2ban on a BinaryLane VPS for a way to block repeated attempts.
On Debian 13 and Ubuntu 26.04, some entries use the process name sshd-session instead of sshd. The command above finds both because they belong to the ssh service.
Older login tools
On Ubuntu 24.04 and Debian 12, last shows recent logins and lastb shows failed logins:
last -n 5 sudo lastb -n 5
These commands are not installed by default on Debian 13 or Ubuntu 26.04. Use the journal search above instead.
3. Install rsyslog on Debian for text log files
This step is optional. The journal contains the authentication and service messages most customers need. Install rsyslog if you prefer traditional text files or a tool requires /var/log/auth.log or /var/log/syslog.
Install rsyslog and logrotate together. Without logrotate, the new text files continue growing without automatic rotation:
sudo apt update sudo apt install -y rsyslog logrotate
rsyslog starts automatically. Confirm that it is active:
systemctl is-active rsyslog
The expected output is:
active
Only new events are written to the text files. syslog and kern.log appear immediately, while auth.log is created after the next login or authentication event. Events recorded before rsyslog was installed remain in the journal only.
After an authentication event, inspect the file:
sudo tail -n 4 /var/log/auth.log
Example output:
2026-10-01T12:19:05+10:00 my-server sshd[1059]: Invalid user baduser from 198.51.100.77 port 4764 2026-10-01T12:19:05+10:00 my-server sshd[1059]: Connection closed by invalid user baduser 198.51.100.77 port 4764 [preauth] 2026-10-01T12:19:05+10:00 my-server sshd[1061]: Accepted publickey for root from 192.0.2.50 port 4766 ssh2: ED25519 SHA256:... 2026-10-01T12:19:05+10:00 my-server sshd[1061]: pam_unix(sshd:session): session opened for user root(uid=0) by (uid=0)
Search the text file:
sudo grep -E 'Accepted|Failed|Invalid' /var/log/auth.log
4. Check that the journal survives a reboot
The systemd journal is persistent on all four tested standard images. Confirm the current configuration:
ls -d /var/log/journal sudo journalctl --list-boots
Example output after at least one reboot:
/var/log/journal IDX BOOT ID FIRST ENTRY LAST ENTRY -1 36ac7cfb2b804a40b6842b53a6e7c582 Thu 2026-10-01 12:17:22 AEST Thu 2026-10-01 12:19:26 AEST 0 5c7a6158e3ff4a048a11b20b03d3a77c Thu 2026-10-01 12:19:36 AEST Thu 2026-10-01 12:20:04 AEST
Two or more boots listed after rebooting confirm that the journal is retained. If only the current boot is available, the journal is stored in memory. This can happen after customising the image or deleting /var/log/journal.
Create a journald drop-in to enable persistent storage:
sudo mkdir -p /etc/systemd/journald.conf.d sudo nano /etc/systemd/journald.conf.d/persistent.conf
Add:
[Journal] Storage=persistent
Restart journald and confirm that the persistent journal directory exists:
sudo systemctl restart systemd-journald ls -d /var/log/journal
With Storage=persistent, journald creates /var/log/journal when required.
5. Control how much disk space logs use
The systemd journal
By default, the persistent journal may use up to 10% of the file system, capped at 4 GB. The effective limit can be lower because journald also reserves free space. On a 40 GB test server, the reported maximum was 3.9 GB.
Check current usage:
sudo journalctl --disk-usage
Example output:
Archived and active journals take up 8.0M in the file system.
Check the effective limit:
sudo journalctl -u systemd-journald -b | grep "System Journal"
Example output:
Oct 01 12:19:36 my-server systemd-journald[218]: System Journal (/var/log/journal/<machine-id>) is 8.0M, max 3.9G, 3.8G free.
Note: On a newly deployed VPS, the limit may be approximately 100 to 220 MB during the first boot. In testing, journald calculated the limit before the disk expanded to the selected plan size. Restarting journald or rebooting recalculated it using the expanded disk.
To set custom limits, create a drop-in file rather than editing /etc/systemd/journald.conf directly:
sudo mkdir -p /etc/systemd/journald.conf.d sudo nano /etc/systemd/journald.conf.d/size.conf
For example:
[Journal] SystemMaxUse=200M MaxRetentionSec=1month
SystemMaxUse limits the disk space used by persistent journal files. MaxRetentionSec removes journal files containing entries older than the specified time. You can use either or both settings.
Apply the configuration and check the new limit:
sudo systemctl restart systemd-journald sudo journalctl -u systemd-journald -n 5 | grep "System Journal"
Example output:
Oct 01 12:19:27 my-server systemd-journald[1412]: System Journal (/var/log/journal/<machine-id>) is 8.0M, max 200.0M, 191.9M free.
Warning: The following vacuum commands permanently delete archived journal files that exceed the selected size or age. Export any logs you need to retain before running them. Active journal files are not removed.
Remove older archived entries immediately:
sudo journalctl --vacuum-size=100M sudo journalctl --vacuum-time=2weeks
Traditional text log files
On Ubuntu, and on Debian after installing logrotate, rsyslog's text files are rotated weekly and four old copies are retained by the standard /etc/logrotate.d/rsyslog policy:
/var/log/syslog
/var/log/mail.log
/var/log/kern.log
/var/log/auth.log
/var/log/user.log
/var/log/cron.log
{
rotate 4
weekly
...
}Edit that policy if you need different retention. For example, change rotate 4 to keep more or fewer archived files, or change weekly to daily or monthly. The systemd logrotate timer runs once each day.
Find logs using the most disk space
sudo du -sh /var/log sudo du -h --max-depth=1 /var/log | sort -h | tail -5
Troubleshooting
/var/log/auth.log or /var/log/syslog does not exist
On Debian, this is expected until you install rsyslog. After installing it, auth.log is created when an authentication event occurs. Log in again, then check the file.
journalctl says you are not seeing messages from other users and the system
Run the command with sudo. Alternatively, add your user to the groups that can read journal and text logs:
sudo usermod -aG systemd-journal,adm YOUR_USERNAME
Replace YOUR_USERNAME with the account name, then log out and back in. Membership in systemd-journal permits journal access, while adm permits access to restricted files in /var/log.
journalctl only shows the current boot
The journal is not persistent. Follow step 4 to configure persistent storage.
The time in auth.log does not match journalctl
Run timedatectl to confirm the server's time zone. journalctl displays times in the server's local time, while text log timestamps include an explicit UTC offset such as +10:00.
Things to know
- Logging is enabled by default. On standard supported images, the main choice is whether you also want traditional text files on Debian.
- The journal and text files overlap but are not identical. Many service and authentication events appear in both, while the journal can contain additional structured entries.
- Logs require free disk space. A full file system can prevent services from writing new entries. Monitor
journalctl --disk-usageand/var/logon systems that log heavily. - Local logs can be changed by root. For records that must survive a server compromise, forward logs to another system. rsyslog supports remote forwarding, and systemd provides
systemd-journal-remote. - Command and file auditing requires a different tool. Recording commands or file access requires an auditing system such as
auditd, which is not installed by default on the tested standard images.
Related articles
- Securing your servers on BinaryLane
- How to install and use fail2ban on a BinaryLane VPS
- What are CIS Hardened Images?
If you require assistance, feel free to submit a support ticket at our helpdesk here: Submit a ticket | BinaryLane
