Q: The `journald` logs on a server are consuming excessive disk space. How do you configure log rotation and size limits for `systemd-journald`?
systemd-journald stores logs in binary format under /var/log/journal/ (persistent) or /run/log/journal/ (volatile, lost on reboot).
#Linux #Linux / SRE — Scenario-Based Interview Questions #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""During an on-call shift, our alerts triggered when a critical Linux production server exhibited this behavior. The interviewer is testing: Systemd journal management, log retention policies.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
systemd-journald stores logs in binary format under /var/log/journal/ (persistent) or /run/log/journal/ (volatile, lost on reboot).
SystemMaxUse=500M: Maximum total disk space the journal can use.SystemKeepFree=1G: Always keep at least 1GB free on the partition.SystemMaxFileSize=50M: Maximum size of individual journal files before rotation.
2️⃣
Remediation & Permanent Safeguards
To control disk usage, edit /etc/systemd/journald.conf: Key directives: Apply immediately: systemctl restart systemd-journald To manually vacuum old logs right now:
[Journal]
SystemMaxUse=500M
SystemKeepFree=1G
SystemMaxFileSize=50M
MaxRetentionSec=30day
MaxRetentionSec=30day: Delete entries older than 30 days.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: SystemMaxUse=500M: Maximum total disk space the journal can use.."
⚡ 60-Second Elevator Pitch Talking Points
- SystemMaxUse=500M: Maximum total disk space the journal can use.
- SystemKeepFree=1G: Always keep at least 1GB free on the partition.
- SystemMaxFileSize=50M: Maximum size of individual journal files before rotation.
Advertisement