Linux

Where Are Linux systemd Journal Logs Stored?

systemd journal storage paths on Linux, when logs persist in /var/log/journal versus /run, and the journalctl commands to read them.

Last updated

The systemd journal keeps binary logs you read with journalctl, not text files you tail. Persistent logs live under /var/log/journal with one subfolder per machine ID. Volatile logs live under /run/log/journal and vanish on reboot, which surprises people after a crash.

If /var/log/journal does not exist, logging falls back to memory only. Creating that directory and restarting systemd-journald turns persistence on. Use journalctl -b for this boot and journalctl --list-boots for history. Many distros still forward to syslog as well.

Where Linux stores this, by platform

Linux
/var/log/journal/[machine-id]

Persistent storage. Each machine ID subfolder holds .journal files. Check /run/log/journal instead if this path is missing, which means logs are memory only.

Frequently asked questions

How do I make journal logs survive a reboot?

Create /var/log/journal with sudo, then restart with sudo systemctl restart systemd-journald. Set Storage=persistent in /etc/systemd/journald.conf to keep the behavior after updates.

Where are old text logs like syslog?

Many distros still forward to /var/log/syslog or /var/log/messages via rsyslog. Those are plain text and rotate separately from the binary journal files.

Notice an outdated path? Let us know.