Skip to content

Configure Persistent systemd Journal Storage and Retention

The systemd journal may keep logs only in volatile storage, which disappears when a host reboots. Configure persistent storage when you need logs from previous boots, then set limits so journal files do not consume the space required by the operating system.

This walkthrough uses a systemd drop-in under /etc, so package updates are less likely to overwrite the settings. The example allows up to 1 GiB of journal data and aims to leave 2 GiB free. Adjust those values to fit the host and your log-retention policy.


Step 1: Inspect the Current Journal State

01

Check the Active Configuration and Disk Use

Baseline

Check the effective journald configuration, current disk use, and which boots have journal records. Save any locally managed settings before changing them. systemd-analyze cat-config is available on current systemd releases; on older systems, inspect /etc/systemd/journald.conf and its drop-in directory directly.

Terminal window
systemd-analyze cat-config systemd/journald.conf
journalctl --disk-usage
journalctl --list-boots
❯ View Expected Console Output
Archived and active journals take up 184.0M in the file system.
-2 ...
-1 ...
0 ...

Step 2: Set Persistent Storage and Limits

02

Add a journald Drop-In

Configuration

Create the persistent journal directory and a dedicated configuration drop-in. With Storage=persistent, journald uses /var/log/journal for persistent data. The size and free-space limits guide cleanup; retention by age is an additional upper bound.

Terminal window
sudo install -d -m 0755 /etc/systemd/journald.conf.d /var/log/journal
sudo tee /etc/systemd/journald.conf.d/60-retention.conf >/dev/null <<'EOF'
[Journal]
Storage=persistent
SystemMaxUse=1G
SystemKeepFree=2G
MaxRetentionSec=30day
EOF
❯ View Expected Console Output
# Confirm the new settings appear in the effective configuration:
systemd-analyze cat-config systemd/journald.conf

Step 3: Activate the New Settings

03

Restart journald and Flush Runtime Logs

Apply

Restart journald to load the drop-in, then flush runtime journal data to persistent storage. On systems with persistent storage configured, systemd normally runs the flush service during boot; this command makes the transition now.

Terminal window
sudo systemctl restart systemd-journald
sudo journalctl --flush
journalctl --disk-usage
journalctl --list-boots
❯ View Expected Console Output
Archived and active journals take up 184.0M in the file system.
0 ...

Step 4: Verify After a Reboot

04

Confirm Logs Survive the Next Restart

Verification

After the next planned reboot, check the boot list and query the previous boot. A previous-boot entry will appear only after the host has rebooted since persistent storage was enabled and journald has collected records for that boot.

Terminal window
journalctl --list-boots
journalctl -b -1 -n 20 --no-pager
❯ View Expected Console Output
-1 ... previous boot
0 ... current boot

For the available storage, retention, and cleanup settings, see the systemd journald.conf manual.

Comments