The Missing Logs
Modern Ubuntu distributions use systemd and its logging daemon, journald, to collect and manage system logs. By default, many Ubuntu server and desktop installations configure journald to store its logs in volatile memory (RAM) within the /run/log/journal/ directory. While this reduces unnecessary write cycles on SSDs and saves disk space, it presents a significant troubleshooting problem: every time you reboot or power cycle the machine, the entire system journal is completely erased, making post-crash diagnostics impossible.
Making the Journal Persistent
To force Ubuntu to retain system logs across reboots, you must reconfigure journald to store its data on the persistent file system. Open a terminal window and use a text editor with root privileges (such as nano) to modify the main journal configuration file. Type sudo nano /etc/systemd/journald.conf and press Enter.
Scroll through the configuration file until you locate the line that reads #Storage=auto. The hash symbol indicates the line is commented out and using the default behavior. Delete the hash symbol and change the word “auto” to “persistent” so the line reads exactly: Storage=persistent. Save the file (Ctrl+O, Enter) and exit the editor (Ctrl+X). Finally, restart the logging service to apply the change by running sudo systemctl restart systemd-journald. Ubuntu will immediately create a permanent directory at /var/log/journal/, and your logs will survive future reboots.