How to Stop Ubuntu from Automatically Deleting Log Files

The Rotating Records

Ubuntu, like most Linux distributions, maintains extensive system logs to help you troubleshoot software crashes, monitor network activity, and audit security events. However, these logs can grow incredibly large. To prevent them from consuming the entire hard drive, Ubuntu uses a utility called logrotate (for older text logs in /var/log) and journald (for systemd logs). These utilities are configured to automatically compress, archive, and eventually delete log files when they reach a certain age or size limit. If you are investigating a long-term intermittent issue or conducting a forensic security audit, this automated deletion might destroy the critical historical data you need.

Extending the Log Retention

To preserve your historical system data and stop Ubuntu from automatically deleting older log files, you must configure the parameters of the systemd journal daemon.

Open a terminal window (Ctrl+Alt+T). You need to edit the main journald configuration file as an administrator. Type sudo nano /etc/systemd/journald.conf and press Enter. Inside the nano text editor, look for parameters governing storage limits. To prevent deletion based on age, find the line #MaxRetentionSec=. Remove the hash (#) to uncomment it, and set it to a larger value, such as MaxRetentionSec=1year (or leave it commented out for no strict time limit). To prevent deletion based on size, find #SystemMaxUse=. Uncomment it and increase the allowed storage size, e.g., SystemMaxUse=10G. Press Ctrl+O to save, Enter to confirm, and Ctrl+X to exit. Finally, restart the logging service by typing sudo systemctl restart systemd-journald.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.