How to Stop Ubuntu from Automatically Deleting Old Logs

The Silent Purge

Ubuntu Linux utilizes the `systemd` journal (`journalctl`) to meticulously log every system event, application error, and kernel panic. To prevent these log files from endlessly expanding and eventually consuming the entire hard drive, `systemd` is configured by default to automatically delete old logs once they reach a certain age or size threshold. While this automated maintenance is excellent for general desktop users, it is a nightmare for system administrators or developers trying to diagnose a rare, intermittent bug that occurred a month ago, only to discover Ubuntu has already vacuumed the relevant log files into oblivion.

Extending the Log Retention Policy

To preserve your historical system data for long-term troubleshooting and stop Ubuntu from automatically deleting old logs prematurely, you must alter the `journald` configuration file.

You need root privileges to modify this file. Open a terminal (Ctrl+Alt+T) and type sudo nano /etc/systemd/journald.conf, then press Enter (provide your password). Use the arrow keys to scroll through the file until you find the commented-out lines (lines starting with `#`) relating to retention limits. Look for `#SystemMaxUse=` and `#MaxRetentionSec=`. To change the behavior, you must uncomment the line (remove the `#`) and define a new value. For example, to tell Ubuntu to keep logs for an entire year instead of a month, change the line to read MaxRetentionSec=1year. To allow the logs to grow much larger before deletion, change the size limit to something like SystemMaxUse=5G (for 5 gigabytes). Save the file (Ctrl+O, Enter) and exit (Ctrl+X). Finally, restart the logging service by typing sudo systemctl restart systemd-journald.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.