How to Disable the Ubuntu ‘Systemd-journald’ Service

The System Logging Daemon

In modern Ubuntu Linux distributions, systemd-journald is the core service responsible for collecting and storing logging data. It intercepts log messages from the kernel, from standard output of system services, and from the traditional syslog interface, storing them in a structured, indexed binary format. These logs are then queried using the journalctl command.

While journald is incredibly powerful for querying logs on a standalone server, there are very specific scenarios where you might want to disable it. For example, if you are building an ultra-minimalist embedded device with strictly limited write-cycles on its flash storage, the constant I/O from journald can degrade the drive. Alternatively, if your organization mandates a strict legacy logging pipeline using a highly customized rsyslog setup and you wish to bypass the journald middleman entirely to save memory, you might attempt to disable it. However, disabling this service on a standard Ubuntu system is highly dangerous and will severely cripple your ability to troubleshoot system errors.

How to Disable the Systemd-journald Service

Because systemd relies so heavily on journald, it is difficult to disable it entirely without breaking the system. The safest approach to “disable” it is to forward all logs elsewhere and stop it from writing to disk, effectively neutralizing its footprint.

Warning: Do not perform this on a production server unless you have an alternative logging mechanism (like rsyslog) fully configured. You will lose the ability to use journalctl.

  1. Open your Ubuntu Terminal or connect via SSH.
  2. Edit the journald configuration file:
sudo nano /etc/systemd/journald.conf
  1. Find the line that says #Storage=auto. Uncomment it (remove the #) and change it to:
Storage=none
  1. Find the line #ForwardToSyslog=yes (or no). If you are using rsyslog, uncomment it and ensure it is set to yes:
ForwardToSyslog=yes
  1. Save the file (Ctrl+O, Enter) and exit Nano (Ctrl+X).
  2. Restart the journald socket to apply the changes (it will now only exist in memory to forward logs, writing nothing to disk):
sudo systemctl restart systemd-journald

Your system will no longer write binary journal logs to /var/log/journal, neutralizing the storage footprint of the service.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.