Where Are Linux systemd Journal Logs Stored?
systemd journal storage paths on Linux, when logs persist in /var/log/journal versus /run, and the journalctl commands to read them.
Last updated
The systemd journal keeps binary logs you read with journalctl, not text files you tail. Persistent logs live under /var/log/journal with one subfolder per machine ID. Volatile logs live under /run/log/journal and vanish on reboot, which surprises people after a crash.
If /var/log/journal does not exist, logging falls back to memory only. Creating that directory and restarting systemd-journald turns persistence on. Use journalctl -b for this boot and journalctl --list-boots for history. Many distros still forward to syslog as well.
Where Linux stores this, by platform
/var/log/journal/[machine-id]
Persistent storage. Each machine ID subfolder holds .journal files. Check /run/log/journal instead if this path is missing, which means logs are memory only.
Frequently asked questions
How do I make journal logs survive a reboot?
Create /var/log/journal with sudo, then restart with sudo systemctl restart systemd-journald. Set Storage=persistent in /etc/systemd/journald.conf to keep the behavior after updates.
Where are old text logs like syslog?
Many distros still forward to /var/log/syslog or /var/log/messages via rsyslog. Those are plain text and rotate separately from the binary journal files.
Notice an outdated path? Let us know.