Skip to content

Linux log investigation with journalctl and system logs

For service desk level 2/3 and MSP technicians who already know the basic Linux commands (see Linux administration basics) and now need to answer "what happened on this server, and when?" from its logs. You'll narrow the systemd journal by unit, boot, time and priority, find the first failure instead of the loudest one, cope with missing logs and time zones, and hand over a clean timeline. Ends with a supervisor-graded investigation on a lab server.

Level
Intermediate
Length
About 70 minutes
Contents
4 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Identify whether logs from before the last reboot exist on a server, who can read them, and why they might be missing
  • Write journalctl commands that narrow output by unit, boot, time window, priority and message pattern
  • Identify the first failure in a journal excerpt and separate it from the errors it caused downstream
  • Build a ticket timeline and log evidence export with a stated time zone and the commands used, without destroying evidence

Course outline

  1. 1.Where Linux logs live, who can read them, and whether earlier boots existLesson · 12 min
  2. 2.Narrowing the haystack with journalctl commandsLesson · 18 min
  3. 3.Reading the story: first failure, not loudest errorLesson · 15 min
  4. 4.Timeline and log evidence for the ticketLesson · 10 min
  5. 5.Linux log investigation with journalctl and system logs: knowledge checkKnowledge check · 14 questions
  6. 6.Linux log investigation with journalctl and system logs: practical exerciseKnowledge check · 1 question
  7. 7.Final exam8 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.