Linux

Where Are Linux System Logs Stored?

Where classic syslog files live under /var/log on Linux, and when the journal replaces them.

Last updated

Traditional Linux logging writes text files under /var/log: syslog for general messages (Debian family), messages for the same role on RHEL systems, auth.log/secure for logins, kern.log for the kernel. Grep, tail and awk are the whole interface.

systemd machines keep a parallel journal (see the journal post) that duplicates much of this, and minimal installs skip the text files entirely. Know which system yours uses before scripting: parsing /var/log/syslog on a journal only host monitors an empty room.

Where Linux stores this, by platform

Linux
/var/log/syslog

Debian/Ubuntu write syslog; RHEL family writes messages and secure instead. auth.log tracks logins. Rotate behavior lives in /etc/logrotate.d/rsyslog. Read live with tail -f.

Frequently asked questions

There is no syslog file on my system. Why?

Check whether rsyslog or syslog-ng is installed and running: systemd only journal setups skip the text files entirely. journalctl -u <service> replaces grep over syslog on those machines. Installing rsyslog restores the classic files alongside the journal.

Logs are eating my disk. How does rotation work?

They rotate via logrotate (daily or weekly configs in /etc/logrotate.d), compressing and eventually deleting generations. A disk filling with logs means a chatty service plus rotation misconfiguration, not syslog itself. Check logrotate status before blaming the writer.

Notice an outdated path? Let us know.