CompTIA Linux+ (XK0-006)Services and User ManagementMedium

A system administrator is troubleshooting a `systemd` service unit that consistently fails to start with an 'exit-code' error. They suspect a problem with the service's environment or dependencies. Which `journalctl` command would be most effective for viewing the logs specifically for this service, including any output during its startup attempt, and filtering for recent entries?

  1. Ajournalctl -b -u myservice.service
  2. Bjournalctl -f -u myservice.service
  3. Cjournalctl -p err -u myservice.service
  4. Djournalctl -u myservice.service --since '1 hour ago'
Show answer & explanation

Correct answer: D. journalctl -u myservice.service --since '1 hour ago'

The `journalctl -u <unit>` command filters logs for a specific `systemd` unit. Adding `--since '1 hour ago'` is crucial for troubleshooting recent failures, as it limits the output to relevant, current entries without overwhelming the user with old logs.

Why the other options are wrong

  • A. The `-b` option shows logs from the current boot, which is helpful but might include too much irrelevant information if the issue is recent and not necessarily boot-related, or if multiple boots occurred.
  • B. The `-f` option 'follows' the log, which is useful for real-time monitoring but not for reviewing past startup attempts.
  • C. The `-p err` option filters by priority 'err' (error), but it might miss other relevant messages (like info or warning) that lead up to the error, and doesn't filter by time.

journalctl for Service Troubleshooting

`journalctl` is used to query and display messages from the `systemd` journal. It's essential for diagnosing service issues.

  • `-u <unit>` filters by specific `systemd` unit.
  • `--since` and `--until` filter by time.
  • Useful for seeing service output and errors.

Memory trick: JOURNAL the UNIT's recent past to find the problem!

More Services and User Management questions