Home / Alt manpages / journald.conf(5)

  • journald.conf(5)
  • File format
  • linux

Put a Safe Size Limit on systemd Journal Logs

An unbounded journal will happily fill a disk during a noisy incident, and journald.conf is where you put a ceiling on that before it happens again. This guide builds a local journald drop-in that caps persistent journal use at a value you choose, plus commands to prove which configuration is active and to undo the change. The examples use systemd 255.4-1ubuntu8.17, the installed package version on this machine.

Allow about ten minutes. You need a shell, systemd-analyze, journalctl and sudo access. Reading the current configuration is unprivileged here. Creating the drop-in and restarting the journal service require elevated privileges.

1. Check where the journal is writing

Start with the effective configuration and current usage:

$ systemd-analyze cat-config systemd/journald.conf
$ journalctl --disk-usage
Archived and active journals take up 136.0M in the file system.

Your output will differ. The first command combines the main file with drop-ins, in the order systemd applies them. On the example machine, the vendor file enables ForwardToSyslog=yes and an administrator drop-in sets SystemMaxUse=1G. Treat that output as the source of truth rather than assuming the commented defaults in /etc/systemd/journald.conf are active.

Checkpoint

Identify whether the journal you care about is persistent under /var/log/journal or runtime-only under /run/log/journal. SystemMaxUse= applies to the former; RuntimeMaxUse= applies to the latter.

2. Choose a drop-in and a limit

Use a drop-in in /etc/systemd/journald.conf.d/ for local policy. This keeps the package-owned main file intact and gives the administrator higher precedence than vendor drop-ins under /usr/lib. Filenames are sorted lexicographically across the drop-in directories, and a later value wins for a single-value setting.

The following example limits persistent journals to 1G and leaves at least 2G free on the file system. Replace those values with capacity appropriate for the host:

$ sudo install -d -m 0755 /etc/systemd/journald.conf.d
$ sudo tee /etc/systemd/journald.conf.d/60-local-storage.conf >/dev/null <<'EOF'
[Journal]
SystemMaxUse=1G
SystemKeepFree=2G
EOF

SystemMaxUse and SystemKeepFree both constrain persistent storage; journald honours the smaller resulting allowance. Size suffixes use binary units, so 1G means 1024 x 1024 x 1024 bytes. This configuration does not delete existing files immediately: size enforcement occurs as journal files are extended, and only archived files can be removed to make room.

Safety boundary

Do not set Storage=none as a shortcut for reducing disk use. It drops journal data, although forwarding to other destinations can continue. If you need runtime limits too, add separate RuntimeMaxUse= and RuntimeKeepFree= values after checking that losing volatile history is acceptable.

3. Verify precedence before applying it

Ask systemd to render the combined configuration again:

$ systemd-analyze cat-config systemd/journald.conf
.../etc/systemd/journald.conf.d/60-local-storage.conf
[Journal]
SystemMaxUse=1G
SystemKeepFree=2G

The path and surrounding entries should appear in the output. If another file later in lexical order contains the same keys, its values win. A common trap is naming a local file 10-local.conf when a vendor file named 90-package.conf overrides it. Use a clearly late filename such as 60-local-storage.conf only after checking the complete output; choose a higher prefix if necessary.

Checkpoint

If the new values do not appear, inspect the filename, section header and spelling. The file must end in .conf, and settings must be under [Journal].

4. Restart journald to load the file

Restart the service with systemd:

$ sudo systemctl restart systemd-journald.service
$ systemctl is-active systemd-journald.service
active

Restarting the service is a service operation and needs root. The installed service documentation says a restart preserves the stream connections held by the service manager, so it is preferred to separately stopping and starting journald. Do not use systemctl stop as a configuration test.

Now check the journal again:

$ journalctl --disk-usage
Archived and active journals take up 136.0M in the file system.

A small current usage value does not prove the cap has been reached; it only proves the command can inspect the journal. The limit is a ceiling, not a target, and it is not an immediate vacuum command. For a configuration error, inspect recent service diagnostics with journalctl -u systemd-journald.service -b --no-pager.

5. Understand storage mode before troubleshooting

The default Storage=auto uses persistent storage when /var/log/journal exists and volatile storage otherwise. Journald can begin a boot in volatile storage and later flush data to persistent storage with journalctl --flush; the boot process normally does this through systemd-journal-flush.service. Therefore, a check made very early in boot can show runtime behaviour even when the final policy is persistent.

Storage=persistent prefers /var/log/journal but can fall back to /run/log/journal during early boot or when the disk is not writable. Storage=volatile keeps logs in memory-backed runtime storage and does not remove old persistent data. Persistent per-user journals also require persistent storage.

If you intentionally need persistent storage and the directory does not exist, create it and let systemd prepare it:

$ sudo mkdir -p /var/log/journal
$ sudo systemd-tmpfiles --create --prefix=/var/log/journal
$ sudo journalctl --flush

This changes storage state and may consume disk space, so check the file system first. Do not run it merely to test a size limit.

6. Recover or undo the change

Warning

Do not delete journal files manually while journald is using them. To remove this guide's configuration, delete only the drop-in you created, then restart the service:

$ sudo rm /etc/systemd/journald.conf.d/60-local-storage.conf
$ sudo systemctl restart systemd-journald.service
$ systemd-analyze cat-config systemd/journald.conf | rg 'System(MaxUse|KeepFree)='

If the final command prints a value from another file, that other file is still active and must be reviewed rather than removed blindly. If you need to reclaim space immediately, use the documented journalctl --vacuum-size= or --vacuum-time= operation after deciding which history can be discarded. Vacuuming is destructive to matching archived entries and is separate from configuring future limits.

Done means

  • Effective config confirmed. systemd-analyze cat-config systemd/journald.conf shows the intended values from the intended file.
  • Service active. systemctl is-active systemd-journald.service reports active after the restart.
  • Usage read correctly. journalctl --disk-usage is understood as current usage, not proof the configured ceiling is full.
  • Right scope identified. You know whether System* or Runtime* limits apply to the journal you are inspecting.
  • Reversible. The drop-in path and restart command are recorded so the change can be reversed safely.