CLI AI

journalctl logs for a service in the last hour

2026-06-20

The command is journalctl -u nginx --since '1 hour ago': -u picks the unit, --since sets the window. Four flags — -u, --since, -p, and -f — cover most of incident triage, and the order below is the order you actually reach for them: from listing everything a service logged to following the error stream live and exporting a rotation-proof copy for a teammate.

1. How do I see logs for a single service?

clai
$ clai show me nginx logs→ journalctl -u nginx

-u stands for unit. Skip it and you get the entire system journal, where your service's messages drown among kernel messages and everything else.

2. How do I narrow the window to the last hour?

clai
$ clai show me nginx logs from the last hour→ journalctl -u nginx --since '1 hour ago'

--since understands human phrasing: today, yesterday, '1 hour ago', '2026-06-20 14:00'. There's a matching --until to cut off the tail after the incident.

3. How do I show only errors?

clai
$ clai show me only nginx errors from today→ journalctl -u nginx --since today -p err

-p is the syslog priority. err shows the error level and everything more severe — critical, alert, emergency. The full scale: emerg, alert, crit, err, warning, notice, info, debug.

4. How do I follow the logs in real time?

clai
$ clai follow nginx logs right now→ journalctl -u nginx -f

It's the equivalent of tail -f, but journald knows about rotation, so this command can't go silent on you. That's the real advantage over reading the file directly.

5. How do I check what happened since the last boot?

clai
$ clai show me this service's errors since the previous boot→ journalctl -u nginx -b -1 -p err

-b is boot. -b -1 is the previous boot, -b 0 or just -b is the current one. Indispensable when the machine went through an unexpected reboot and you need to know why.

6. How do I hand the log to a teammate?

clai
$ clai export nginx logs from today to a file without pagination→ journalctl -u nginx --since today --no-pager -o short-iso > nginx-today.log

--no-pager removes less, which would otherwise hang the command in a non-interactive environment. -o short-iso gives ISO-8601 timestamps that sort correctly and don't depend on locale.

Gotchas

  • -u takes a unit name, not a process name. journalctl -u nginx works, journalctl -u /usr/sbin/nginx doesn't. systemctl list-units --type=service lists the unit names.
  • The journal doesn't always survive a reboot. If Storage=volatile is set in /etc/systemd/journald.conf, history is lost on restart. Check whether /var/log/journal exists.
  • User and system units are separate. For services running under your own user, you need journalctl --user -u name, or you'll find nothing.

Related questions

How do I see just the last N lines? journalctl -u nginx -n 50. By default journalctl shows everything from the beginning, which is unwieldy on a large journal.

Why is journalctl better than reading the file in /var/log? It knows about rotation, filters by unit, priority, and time, and shows logs for services that never write to a file at all.

How do I cap the size of the journal? Set SystemMaxUse=500M in /etc/systemd/journald.conf, then systemctl restart systemd-journald. For a one-off cleanup: journalctl --vacuum-size=200M.

See also

Stop memorizing journalctl flags — describe the incident and CliAI writes the command. Install it in one line.