Home / Alt manpages / journald.conf.d(5)

  • journald.conf.d(5)
  • File format
  • linux

Cap Journal Size and Retention with journald.conf.d

The systemd journal grows quietly until a disk fills up, usually the same week you needed the logs from three months ago. This guide builds a drop-in that caps persistent journal data at 1 GiB, leaves 2 GiB free, and drops entries older than a month, then checks it and shows you how to undo it.

Allow about fifteen minutes. You need a shell, systemd 255 or a nearby release, and sudo access. The examples use the installed systemd 255.4-1ubuntu8.17 package. They change system logging configuration and restart systemd-journald, so use a maintenance window on a busy production machine. The values here are examples, not a universal retention policy.

1. Check the installed version and current usage

Start with read-only checks. Reading all journal files may need membership of a journal-reading group or sudo, but these two do not:

$ systemd --version | head -1
systemd 255 (255.4-1ubuntu8.17)
$ journalctl --disk-usage
Archived and active journals take up ... on disk.

The size line is host-specific. Record it before changing anything. If the journal already exceeds your planned limit, the new configuration will not delete data immediately: archived files are only removed when journald next vacuums to meet its limits.

Checkpoint

You know the installed systemd release and the current journal footprint. If this host has a formal retention or audit requirement, stop here and get the approved values instead of copying the examples.

2. See which configuration files are being merged

  • Three search paths. journald reads the main configuration and drop-ins from /usr/lib/systemd/, /usr/local/lib/systemd/, and /etc/systemd/.
  • Drop-ins win. They have higher precedence than the main file.
  • Sort order decides ties. Files ending in .conf are sorted lexicographically across those directories, and the last value for a single-value option wins.

Ask systemd to show the merged view before writing anything:

$ systemd-analyze cat-config systemd/journald.conf
# /etc/systemd/journald.conf
...
[Journal]
...
# /usr/lib/systemd/journald.conf.d/...
...

Your output will differ. Look for existing assignments to Storage, SystemMaxUse, SystemKeepFree, and MaxRetentionSec. A later file can override an earlier one, so a new file named 60-retention.conf is not guaranteed to win if another drop-in sorts after it.

3. Choose values that fit the machine

This example makes persistent storage explicit and sets three limits:

  • Storage=persistent prefers /var/log/journal, falling back to runtime storage when the disk is unavailable.
  • SystemMaxUse=1G caps persistent journal usage at 1 GiB.
  • SystemKeepFree=2G tells journald to leave at least 2 GiB free, with the smaller effective allowance applying.
  • MaxRetentionSec=1month deletes journal files containing entries older than one month.

Do not set SystemKeepFree higher than the space the host can spare without understanding the result. Size limits apply to persistent storage under /var/log/journal; runtime limits such as RuntimeMaxUse apply to /run/log/journal. If you need a runtime cap too, add one deliberately rather than assuming SystemMaxUse covers both.

4. Create one administrator drop-in

Create the directory and file with elevated privileges. The 60- prefix makes the intended priority visible, but check step 2 first for later files that might outrank it:

$ sudo install -d -m 0755 /etc/systemd/journald.conf.d
$ sudo tee /etc/systemd/journald.conf.d/60-retention.conf > /dev/null <<'EOF'
[Journal]
Storage=persistent
SystemMaxUse=1G
SystemKeepFree=2G
MaxRetentionSec=1month
EOF
$ sudo chmod 0644 /etc/systemd/journald.conf.d/60-retention.conf

Do not put these settings in a file under /usr/lib; package updates own that area. Do not edit the generated output from systemd-analyze cat-config. The file above is the only persistent change this guide makes.

Checkpoint

Inspect exactly what was written:

$ sudo sed -n '1,20p' /etc/systemd/journald.conf.d/60-retention.conf
[Journal]
Storage=persistent
SystemMaxUse=1G
SystemKeepFree=2G
MaxRetentionSec=1month

5. Verify precedence before activating it

Read the merged result and check that the values you intend to use actually survive:

$ systemd-analyze cat-config systemd/journald.conf | tail -30
...
[Journal]
Storage=persistent
SystemMaxUse=1G
SystemKeepFree=2G
MaxRetentionSec=1month

The exact placement depends on the other files installed on the host. If a later drop-in assigns a different value, rename your file to a suitable later prefix after reviewing the conflict. Do not create several competing local files just to make the output look right; keep one authoritative local policy.

6. Restart journald and flush persistent storage

Warning

This step changes the running logging daemon. Restart it with systemctl restart, not separate stop and start commands. The systemd-journald manual documents that the stream connections supplied by the service manager survive this form of restart, while stopping the daemon separately is not recommended.

$ sudo systemctl restart systemd-journald
$ systemctl is-active systemd-journald
active
$ sudo journalctl --flush

--flush moves journal data from /run to /var when persistent logging is enabled and the filesystem is available. It does not make an unavailable or unwritable disk usable. A successful restart and flush normally print no success message, so the active result is the useful checkpoint.

7. Check the result and understand the limits

Confirm the daemon is healthy and inspect usage again:

$ systemctl is-active systemd-journald
active
$ journalctl --disk-usage
Archived and active journals take up ... on disk.
$ journalctl -b -n 20 --no-pager
... recent entries ...

The journal size may not drop to 1 GiB immediately. Only archived files are removed during cleanup, and an active file can keep the total above a nominal limit until rotation. MaxRetentionSec also works on journal files, so an entry's age and whether its file can be removed both matter.

Do not use journalctl --vacuum-time or --vacuum-size as a substitute for the configuration. Those are immediate cleanup operations. If you use one, read its effect first and remember that deleting archived logs is irreversible.

8. Roll back the drop-in

If the policy is wrong, remove only the file created in step 4, then restart journald and flush again:

$ sudo rm /etc/systemd/journald.conf.d/60-retention.conf
$ sudo systemctl restart systemd-journald
$ sudo journalctl --flush
$ systemd-analyze cat-config systemd/journald.conf | tail -30

This restores the values supplied by the remaining main configuration and drop-ins. It does not restore journal files already removed by an earlier retention or vacuum operation. If you changed an existing file instead of creating the one shown here, restore its backup rather than running this removal command.

Done means

  • Version and usage checked first, before anything was changed.
  • Merged configuration inspected for later drop-ins and conflicting values.
  • One administrator-owned file under /etc/systemd/journald.conf.d/ defines the chosen policy.
  • journald active after a controlled restart, with persistent data flushed.
  • Usage and recent entries checked without assuming cleanup is instant.
  • Rollback understood: you know how to remove the drop-in, and that deleted journal data cannot be recovered by rollback.