CompTIA Linux+ (XK0-006)Services and User ManagementEasy

A system administrator is debugging a custom `systemd` service unit named `mywebapp.service` that fails to start correctly. The administrator suspects an issue with the environment variables or command execution path. Which `journalctl` command would be most effective for viewing detailed logs specifically related to this service, including any output to standard error?

  1. Ajournalctl --since "1 hour ago" -u mywebapp.service
  2. Bjournalctl -u mywebapp.service -e
  3. Cjournalctl -u mywebapp.service -f
  4. Djournalctl -u mywebapp.service --no-pager -o verbose
Show answer & explanation

Correct answer: C. journalctl -u mywebapp.service -f

The `journalctl -u <unit_name> -f` command is ideal for real-time debugging. It displays logs for the specified `systemd` unit and then 'follows' the log output, showing new entries as they arrive, which is crucial when trying to catch startup failures or runtime issues.

Why the other options are wrong

  • A. This command filters by time, which is useful but doesn't provide real-time following for active debugging.
  • B. The `-e` option jumps to the end of the journal, which is useful for seeing the latest entries, but it doesn't follow the log output.
  • D. The `-o verbose` option provides more detailed field output, but `--no-pager` and verbose output aren't explicitly for catching startup failures in real-time.

Following systemd Unit Logs

Use `journalctl -u <unit> -f` to view `systemd` unit logs in real-time, displaying new entries as they are generated.

  • The `-f` (follow) option continuously outputs new log entries.
  • Essential for troubleshooting services that fail to start or have intermittent issues.
  • Filters logs specifically for a `systemd` unit.

Memory trick: Journal's 'U' for 'Unit', 'F' for 'Follow'.

More Services and User Management questions