This guide explains how to find, read and retain system logs on Ubuntu and Debian. It also shows how to add traditional text log files on Debian and control how much disk space logs use.


These steps apply to standard BinaryLane images running Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12 or Debian 13. 


Logging is already enabled on these images and persists across reboots. The main difference is where the logs are stored:

  • Ubuntu uses the systemd journal and also writes traditional files such as /var/log/syslog and /var/log/auth.log.

  • Debian uses the systemd journal by default. Traditional auth.log and syslog files are unavailable until you install rsyslog.


Before you start


Prerequisites: 

  • A VPS running one of the supported images listed above.

  • Root access over SSH, or a user account with sudo access.


The commands use sudo. If you are logged in as root, you can omit it.


Important: The operating system and its logging configuration are customer-managed. BinaryLane CIS hardened images use different logging settings. See What are CIS Hardened Images? if your server uses a hardened image.

 



TABLE OF CONTENTS





1. See what your server is already logging


Check which logging services are running:


systemctl is-active systemd-journald rsyslog


On Ubuntu, the expected output is:


active
active


On Debian, the expected output is:


active
inactive


systemd-journald manages the systemd journal, where services and the kernel record events. rsyslog writes traditional text log files. Standard Debian 12 and Debian 13 images do not include rsyslog, so it reports inactive.


List the available log files:


ls /var/log


On Ubuntu, the list includes traditional logs such as:


alternatives.log  apt  auth.log  btmp  cloud-init.log  dpkg.log  journal
kern.log  lastlog  syslog  unattended-upgrades  wtmp  ...


On Debian, auth.log, kern.log and syslog are absent by default:


btmp  cloud-init-output.log  cloud-init.log  journal  lastlog  wtmp  ...


The relevant events are still available through the journal. The following table summarises the tested standard images:


Logging featureUbuntu 24.04Ubuntu 26.04Debian 12Debian 13
Persistent systemd journalYesYesYesYes
rsyslog text filesInstalledInstalledNot installedNot installed
logrotateInstalledInstalledNot installedNot installed
last and lastbInstalledNot installedInstalledNot installed



2. Read logs with journalctl


journalctl works on all four supported images. Display the 50 most recent entries:


sudo journalctl -n 50


Common searches include:


What you want to seeCommand
One service's logssudo journalctl -u ssh
Entries from the last hoursudo journalctl --since "1 hour ago"
A specific time windowsudo journalctl --since "2026-10-01 12:00" --until "2026-10-01 13:00"
Errors since the current bootsudo journalctl -b -p err
Kernel messagessudo journalctl -k
The previous bootsudo journalctl -b -1
New entries as they arrivesudo journalctl -f - press Ctrl+C to stop


The OpenSSH service is named ssh on these Ubuntu and Debian images. Times are shown in the server's configured time zone. Check it with:


timedatectl


Find successful and failed SSH logins


sudo journalctl -u ssh --since "today" | grep -E 'Accepted|Failed|Invalid'


Example output:


Oct 01 12:19:04 my-server sshd[1059]: Invalid user baduser from 198.51.100.77 port 4764
Oct 01 12:19:05 my-server sshd[1061]: Accepted publickey for root from 192.0.2.50 port 4766 ssh2: ED25519 SHA256:...


Accepted records a successful login. Invalid user and Failed password record failed attempts. Internet-facing servers commonly receive unsuccessful login attempts. See How to install and use fail2ban on a BinaryLane VPS for a way to block repeated attempts.


On Debian 13 and Ubuntu 26.04, some entries use the process name sshd-session instead of sshd. The command above finds both because they belong to the ssh service.


Older login tools


On Ubuntu 24.04 and Debian 12, last shows recent logins and lastb shows failed logins:


last -n 5
sudo lastb -n 5


These commands are not installed by default on Debian 13 or Ubuntu 26.04. Use the journal search above instead.



3. Install rsyslog on Debian for text log files


This step is optional. The journal contains the authentication and service messages most customers need. Install rsyslog if you prefer traditional text files or a tool requires /var/log/auth.log or /var/log/syslog.


Install rsyslog and logrotate together. Without logrotate, the new text files continue growing without automatic rotation:


sudo apt update
sudo apt install -y rsyslog logrotate


rsyslog starts automatically. Confirm that it is active:


systemctl is-active rsyslog


The expected output is:


active


Only new events are written to the text files. syslog and kern.log appear immediately, while auth.log is created after the next login or authentication event. Events recorded before rsyslog was installed remain in the journal only.


After an authentication event, inspect the file:


sudo tail -n 4 /var/log/auth.log


Example output:


2026-10-01T12:19:05+10:00 my-server sshd[1059]: Invalid user baduser from 198.51.100.77 port 4764
2026-10-01T12:19:05+10:00 my-server sshd[1059]: Connection closed by invalid user baduser 198.51.100.77 port 4764 [preauth]
2026-10-01T12:19:05+10:00 my-server sshd[1061]: Accepted publickey for root from 192.0.2.50 port 4766 ssh2: ED25519 SHA256:...
2026-10-01T12:19:05+10:00 my-server sshd[1061]: pam_unix(sshd:session): session opened for user root(uid=0) by (uid=0)


Search the text file:


sudo grep -E 'Accepted|Failed|Invalid' /var/log/auth.log



4. Check that the journal survives a reboot


The systemd journal is persistent on all four tested standard images. Confirm the current configuration:


ls -d /var/log/journal
sudo journalctl --list-boots


Example output after at least one reboot:


/var/log/journal
IDX BOOT ID                          FIRST ENTRY                  LAST ENTRY
 -1 36ac7cfb2b804a40b6842b53a6e7c582 Thu 2026-10-01 12:17:22 AEST Thu 2026-10-01 12:19:26 AEST
  0 5c7a6158e3ff4a048a11b20b03d3a77c Thu 2026-10-01 12:19:36 AEST Thu 2026-10-01 12:20:04 AEST


Two or more boots listed after rebooting confirm that the journal is retained. If only the current boot is available, the journal is stored in memory. This can happen after customising the image or deleting /var/log/journal.


Create a journald drop-in to enable persistent storage:


sudo mkdir -p /etc/systemd/journald.conf.d
sudo nano /etc/systemd/journald.conf.d/persistent.conf


Add:


[Journal]
Storage=persistent


Restart journald and confirm that the persistent journal directory exists:


sudo systemctl restart systemd-journald
ls -d /var/log/journal


With Storage=persistent, journald creates /var/log/journal when required.



5. Control how much disk space logs use


The systemd journal


By default, the persistent journal may use up to 10% of the file system, capped at 4 GB. The effective limit can be lower because journald also reserves free space. On a 40 GB test server, the reported maximum was 3.9 GB.


Check current usage:


sudo journalctl --disk-usage


Example output:


Archived and active journals take up 8.0M in the file system.


Check the effective limit:


sudo journalctl -u systemd-journald -b | grep "System Journal"


Example output:


Oct 01 12:19:36 my-server systemd-journald[218]: System Journal (/var/log/journal/<machine-id>) is 8.0M, max 3.9G, 3.8G free.


Note: On a newly deployed VPS, the limit may be approximately 100 to 220 MB during the first boot. In testing, journald calculated the limit before the disk expanded to the selected plan size. Restarting journald or rebooting recalculated it using the expanded disk.

 

To set custom limits, create a drop-in file rather than editing /etc/systemd/journald.conf directly:


sudo mkdir -p /etc/systemd/journald.conf.d
sudo nano /etc/systemd/journald.conf.d/size.conf


For example:


[Journal]
SystemMaxUse=200M
MaxRetentionSec=1month


SystemMaxUse limits the disk space used by persistent journal files. MaxRetentionSec removes journal files containing entries older than the specified time. You can use either or both settings.


Apply the configuration and check the new limit:


sudo systemctl restart systemd-journald
sudo journalctl -u systemd-journald -n 5 | grep "System Journal"


Example output:


Oct 01 12:19:27 my-server systemd-journald[1412]: System Journal (/var/log/journal/<machine-id>) is 8.0M, max 200.0M, 191.9M free.


Warning: The following vacuum commands permanently delete archived journal files that exceed the selected size or age. Export any logs you need to retain before running them. Active journal files are not removed.

 

Remove older archived entries immediately:


sudo journalctl --vacuum-size=100M
sudo journalctl --vacuum-time=2weeks


Traditional text log files


On Ubuntu, and on Debian after installing logrotate, rsyslog's text files are rotated weekly and four old copies are retained by the standard /etc/logrotate.d/rsyslog policy:


/var/log/syslog
/var/log/mail.log
/var/log/kern.log
/var/log/auth.log
/var/log/user.log
/var/log/cron.log
{
    rotate 4
    weekly
    ...
}


Edit that policy if you need different retention. For example, change rotate 4 to keep more or fewer archived files, or change weekly to daily or monthly. The systemd logrotate timer runs once each day.


Find logs using the most disk space


sudo du -sh /var/log
sudo du -h --max-depth=1 /var/log | sort -h | tail -5




Troubleshooting


/var/log/auth.log or /var/log/syslog does not exist

On Debian, this is expected until you install rsyslog. After installing it, auth.log is created when an authentication event occurs. Log in again, then check the file.


journalctl says you are not seeing messages from other users and the system

Run the command with sudo. Alternatively, add your user to the groups that can read journal and text logs:


sudo usermod -aG systemd-journal,adm YOUR_USERNAME


Replace YOUR_USERNAME with the account name, then log out and back in. Membership in systemd-journal permits journal access, while adm permits access to restricted files in /var/log.


journalctl only shows the current boot

The journal is not persistent. Follow step 4 to configure persistent storage.


The time in auth.log does not match journalctl

Run timedatectl to confirm the server's time zone. journalctl displays times in the server's local time, while text log timestamps include an explicit UTC offset such as +10:00.




Things to know


  • Logging is enabled by default. On standard supported images, the main choice is whether you also want traditional text files on Debian.

  • The journal and text files overlap but are not identical. Many service and authentication events appear in both, while the journal can contain additional structured entries.

  • Logs require free disk space. A full file system can prevent services from writing new entries. Monitor journalctl --disk-usage and /var/log on systems that log heavily.

  • Local logs can be changed by root. For records that must survive a server compromise, forward logs to another system. rsyslog supports remote forwarding, and systemd provides systemd-journal-remote.

  • Command and file auditing requires a different tool. Recording commands or file access requires an auditing system such as auditd, which is not installed by default on the tested standard images.







If you require assistance, feel free to submit a support ticket at our helpdesk here: Submit a ticket | BinaryLane