The command is journalctl -u nginx --since '1 hour ago': -u picks the unit, --since sets the window. Four flags — -u, --since, -p, and -f — cover most of incident triage, and the order below is the order you actually reach for them: from listing everything a service logged to following the error stream live and exporting a rotation-proof copy for a teammate.
1. How do I see logs for a single service?
$ clai show me nginx logs→ journalctl -u nginx
-u stands for unit. Skip it and you get the entire system journal, where your service's messages drown among kernel messages and everything else.
2. How do I narrow the window to the last hour?
$ clai show me nginx logs from the last hour→ journalctl -u nginx --since '1 hour ago'
--since understands human phrasing: today, yesterday, '1 hour ago', '2026-06-20 14:00'. There's a matching --until to cut off the tail after the incident.
3. How do I show only errors?
$ clai show me only nginx errors from today→ journalctl -u nginx --since today -p err
-p is the syslog priority. err shows the error level and everything more severe — critical, alert, emergency. The full scale: emerg, alert, crit, err, warning, notice, info, debug.
4. How do I follow the logs in real time?
$ clai follow nginx logs right now→ journalctl -u nginx -f
It's the equivalent of tail -f, but journald knows about rotation, so this command can't go silent on you. That's the real advantage over reading the file directly.
5. How do I check what happened since the last boot?
$ clai show me this service's errors since the previous boot→ journalctl -u nginx -b -1 -p err
-b is boot. -b -1 is the previous boot, -b 0 or just -b is the current one. Indispensable when the machine went through an unexpected reboot and you need to know why.
6. How do I hand the log to a teammate?
$ clai export nginx logs from today to a file without pagination→ journalctl -u nginx --since today --no-pager -o short-iso > nginx-today.log
--no-pager removes less, which would otherwise hang the command in a non-interactive environment. -o short-iso gives ISO-8601 timestamps that sort correctly and don't depend on locale.
Gotchas
-utakes a unit name, not a process name.journalctl -u nginxworks,journalctl -u /usr/sbin/nginxdoesn't.systemctl list-units --type=servicelists the unit names.- The journal doesn't always survive a reboot. If
Storage=volatileis set in/etc/systemd/journald.conf, history is lost on restart. Check whether/var/log/journalexists. - User and system units are separate. For services running under your own user, you need
journalctl --user -u name, or you'll find nothing.
Related questions
How do I see just the last N lines? journalctl -u nginx -n 50. By default journalctl shows everything from the beginning, which is unwieldy on a large journal.
Why is journalctl better than reading the file in /var/log? It knows about rotation, filters by unit, priority, and time, and shows logs for services that never write to a file at all.
How do I cap the size of the journal? Set SystemMaxUse=500M in /etc/systemd/journald.conf, then systemctl restart systemd-journald. For a one-off cleanup: journalctl --vacuum-size=200M.
See also
- Tail multiple log files at once
- The process that won't die
- Sweep old logs and backups with one sentence
Stop memorizing journalctl flags — describe the incident and CliAI writes the command. Install it in one line.