Put a Safe Size Limit on systemd Journal Logs
An unbounded journal will happily fill a disk during a noisy incident, and journald.conf is where you put a ceiling on that before it happens again. This guide builds a local journald drop-in that caps persistent journal use at a value you choose, plus commands to prove which configuration is active and to undo the change. The examples use systemd 255.4-1ubuntu8.17, the installed package version on this machine.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell, systemd-analyze, journalctl and sudo access. Reading the current configuration is unprivileged here. Creating the drop-in and restarting the journal service require elevated privileges.
1. Check where the journal is writing
Start with the effective configuration and current usage:
$ systemd-analyze cat-config systemd/journald.conf
$ journalctl --disk-usage
Archived and active journals take up 136.0M in the file system.
Your output will differ. The first command combines the main file with drop-ins, in the order systemd applies them. On the example machine, the vendor file enables ForwardToSyslog=yes and an administrator drop-in sets SystemMaxUse=1G. Treat that output as the source of truth rather than assuming the commented defaults in /etc/systemd/journald.conf are active.
Checkpoint
Identify whether the journal you care about is persistent under /var/log/journal or runtime-only under /run/log/journal. SystemMaxUse= applies to the former; RuntimeMaxUse= applies to the latter.
2. Choose a drop-in and a limit
Use a drop-in in /etc/systemd/journald.conf.d/ for local policy. This keeps the package-owned main file intact and gives the administrator higher precedence than vendor drop-ins under /usr/lib. Filenames are sorted lexicographically across the drop-in directories, and a later value wins for a single-value setting.
The following example limits persistent journals to 1G and leaves at least 2G free on the file system. Replace those values with capacity appropriate for the host:
$ sudo install -d -m 0755 /etc/systemd/journald.conf.d
$ sudo tee /etc/systemd/journald.conf.d/60-local-storage.conf >/dev/null <<'EOF'
[Journal]
SystemMaxUse=1G
SystemKeepFree=2G
EOF
SystemMaxUse and SystemKeepFree both constrain persistent storage; journald honours the smaller resulting allowance. Size suffixes use binary units, so 1G means 1024 x 1024 x 1024 bytes. This configuration does not delete existing files immediately: size enforcement occurs as journal files are extended, and only archived files can be removed to make room.
Safety boundary
Do not set Storage=none as a shortcut for reducing disk use. It drops journal data, although forwarding to other destinations can continue. If you need runtime limits too, add separate RuntimeMaxUse= and RuntimeKeepFree= values after checking that losing volatile history is acceptable.
3. Verify precedence before applying it
Ask systemd to render the combined configuration again:
$ systemd-analyze cat-config systemd/journald.conf
.../etc/systemd/journald.conf.d/60-local-storage.conf
[Journal]
SystemMaxUse=1G
SystemKeepFree=2G
The path and surrounding entries should appear in the output. If another file later in lexical order contains the same keys, its values win. A common trap is naming a local file 10-local.conf when a vendor file named 90-package.conf overrides it. Use a clearly late filename such as 60-local-storage.conf only after checking the complete output; choose a higher prefix if necessary.
Checkpoint
If the new values do not appear, inspect the filename, section header and spelling. The file must end in .conf, and settings must be under [Journal].
4. Restart journald to load the file
Restart the service with systemd:
$ sudo systemctl restart systemd-journald.service
$ systemctl is-active systemd-journald.service
active
Restarting the service is a service operation and needs root. The installed service documentation says a restart preserves the stream connections held by the service manager, so it is preferred to separately stopping and starting journald. Do not use systemctl stop as a configuration test.
Now check the journal again:
$ journalctl --disk-usage
Archived and active journals take up 136.0M in the file system.
A small current usage value does not prove the cap has been reached; it only proves the command can inspect the journal. The limit is a ceiling, not a target, and it is not an immediate vacuum command. For a configuration error, inspect recent service diagnostics with journalctl -u systemd-journald.service -b --no-pager.
5. Understand storage mode before troubleshooting
The default Storage=auto uses persistent storage when /var/log/journal exists and volatile storage otherwise. Journald can begin a boot in volatile storage and later flush data to persistent storage with journalctl --flush; the boot process normally does this through systemd-journal-flush.service. Therefore, a check made very early in boot can show runtime behaviour even when the final policy is persistent.
Storage=persistent prefers /var/log/journal but can fall back to /run/log/journal during early boot or when the disk is not writable. Storage=volatile keeps logs in memory-backed runtime storage and does not remove old persistent data. Persistent per-user journals also require persistent storage.
If you intentionally need persistent storage and the directory does not exist, create it and let systemd prepare it:
$ sudo mkdir -p /var/log/journal
$ sudo systemd-tmpfiles --create --prefix=/var/log/journal
$ sudo journalctl --flush
This changes storage state and may consume disk space, so check the file system first. Do not run it merely to test a size limit.
6. Recover or undo the change
Warning
Do not delete journal files manually while journald is using them. To remove this guide's configuration, delete only the drop-in you created, then restart the service:
$ sudo rm /etc/systemd/journald.conf.d/60-local-storage.conf
$ sudo systemctl restart systemd-journald.service
$ systemd-analyze cat-config systemd/journald.conf | rg 'System(MaxUse|KeepFree)='
If the final command prints a value from another file, that other file is still active and must be reviewed rather than removed blindly. If you need to reclaim space immediately, use the documented journalctl --vacuum-size= or --vacuum-time= operation after deciding which history can be discarded. Vacuuming is destructive to matching archived entries and is separate from configuring future limits.
Done means
- Effective config confirmed.
systemd-analyze cat-config systemd/journald.confshows the intended values from the intended file. - Service active.
systemctl is-active systemd-journald.servicereportsactiveafter the restart. - Usage read correctly.
journalctl --disk-usageis understood as current usage, not proof the configured ceiling is full. - Right scope identified. You know whether
System*orRuntime*limits apply to the journal you are inspecting. - Reversible. The drop-in path and restart command are recorded so the change can be reversed safely.