• Morethanevil@lemmy.fedifriends.social
    link
    fedilink
    arrow-up
    147
    ·
    3 months ago

    Cleanup

    Check current disk usage:

    sudo journalctl --disk-usage

    Use rotate function:

    sudo journalctl --rotate

    Or

    Remove all logs and keep the last 2 days:

    sudo journalctl --vacuum-time=2days

    Or

    Remove all logs and only keep the last 100MB:

    sudo journalctl --vacuum-size=100M

    How to read logs:

    Follow specific log for a service:

    sudo journalctl -fu SERVICE

    Show extended log info and print the last lines of a service:

    sudo journalctl -xeu SERVICE

  • RobotZap10000@feddit.nl
    link
    fedilink
    arrow-up
    30
    ·
    3 months ago

    Try 60GB of system logs after 15 minutes of use. My old laptop’s wifi card worked just fine, but spammed the error log with some corrected error. Adding pci=noaer to grub config fixed it.

    • xilophor@lemmy.world
      link
      fedilink
      English
      arrow-up
      22
      ·
      3 months ago

      I had an issue on my PC (assuming faulty graphics driver or bug after waking from sleep) that caused my syslog file to reach 500GiB. Yes, 500GiB.

  • wildbus8979@sh.itjust.works
    link
    fedilink
    arrow-up
    26
    ·
    edit-2
    3 months ago

    Fucking blows my mind that journald broke what is essentially the default behavior of every distro’s use of logrotate and no one bats an eye.

    • Regalia
      link
      fedilink
      arrow-up
      26
      ·
      edit-2
      3 months ago

      I’m not sure if you’re joking or not, but the behavior of journald is fairly dynamic and can be configured to an obnoxious degree, including compression and sealing.

      By default, the size limit is 4GB:

      SystemMaxUse= and RuntimeMaxUse= control how much disk space the journal may use up at most. SystemKeepFree= and RuntimeKeepFree= control how much disk space systemd-journald shall leave free for other uses. systemd-journald will respect both limits and use the smaller of the two values.

      The first pair defaults to 10% and the second to 15% of the size of the respective file system, but each value is capped to 4G.

  • hushable@lemmy.world
    link
    fedilink
    arrow-up
    25
    ·
    edit-2
    3 months ago

    Once I had a mission critical service crash because the disk got full, turns out there was a typo on the logrotate config and as a result the logs were not being cleaned up at all.

    edit: I should add that I used the commands shared in this post to free up space and bring the service back up

  • muhyb@programming.dev
    link
    fedilink
    arrow-up
    15
    ·
    3 months ago

    This once happened to me on my pi-hole. It’s an old netbook with 250 GB HDD. Pi-hole stopped working and I checked the netbook. There was a 242 GB log file. :)

  • zoey
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 months ago

    Recently had the jellyfin log directory take up 200GB, checked the forums and saw someone with the same problem but 1TB instead.

    • Agent641@lemmy.world
      link
      fedilink
      arrow-up
      16
      ·
      edit-2
      3 months ago

      2024-03-28 16:37:12:017 - Everythings fine

      2024-03-28 16:37:12:016 - Everythings fine

      2024-03-28 16:37:12:015 - Everythings fine

  • Scribbd@feddit.nl
    link
    fedilink
    arrow-up
    5
    ·
    3 months ago

    I recently discovered the company I work for, has an S3 bucket with network flow logs of several TB. It contains all network activity if the past 8 years.

    Not because we needed it. No, the lifecycle policy wasn’t configured correctly.

  • alien@lemm.ee
    link
    fedilink
    arrow-up
    5
    ·
    3 months ago

    I couldn’t tell for a solid minute if the title was telling me to clear the journal or not