Linux log investigation with journalctl and system logs
For service desk level 2/3 and MSP technicians who already know the basic Linux commands (see Linux administration basics) and now need to answer "what happened on this server, and when?" from its logs. You'll narrow the systemd journal by unit, boot, time and priority, find the first failure instead of the loudest one, cope with missing logs and time zones, and hand over a clean timeline. Ends with a supervisor-graded investigation on a lab server.
- Level
- Intermediate
- Length
- About 70 minutes
- Contents
- 4 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify whether logs from before the last reboot exist on a server, who can read them, and why they might be missing
- Write journalctl commands that narrow output by unit, boot, time window, priority and message pattern
- Identify the first failure in a journal excerpt and separate it from the errors it caused downstream
- Build a ticket timeline and log evidence export with a stated time zone and the commands used, without destroying evidence
Course outline
- 1.Where Linux logs live, who can read them, and whether earlier boots existLesson · 12 min
- 2.Narrowing the haystack with journalctl commandsLesson · 18 min
- 3.Reading the story: first failure, not loudest errorLesson · 15 min
- 4.Timeline and log evidence for the ticketLesson · 10 min
- 5.Linux log investigation with journalctl and system logs: knowledge checkKnowledge check · 14 questions
- 6.Linux log investigation with journalctl and system logs: practical exerciseKnowledge check · 1 question
- 7.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.