How to Stop Ubuntu from Automatically Deleting Old Logs

The Disappearing Evidence

Ubuntu (and most Linux distributions) utilizes systemd-journald and legacy syslog utilities to meticulously record every event that happens on your system—from kernel panics to failed SSH login attempts. Because these text files grow continuously, Ubuntu employs a background utility called logrotate. By default, logrotate is configured to automatically compress older logs and permanently delete them after a certain period (e.g., 4 weeks) to prevent them from filling up your hard drive. If you are investigating a complex security breach that occurred two months ago, you will find the crucial evidence has been automatically destroyed.

Preserving Your History

To maintain a complete historical audit trail and stop Ubuntu from automatically deleting old system logs, you must modify the configuration files governing log rotation and the journal daemon.

Open your terminal (Ctrl+Alt+T). First, handle the systemd journal. Type sudo nano /etc/systemd/journald.conf and press Enter. Look for the line that says #MaxRetentionSec=. Remove the ‘#’ to uncomment it, and change it to MaxRetentionSec=0 (which means keep forever) or a very large number like MaxRetentionSec=365day. Save and exit (Ctrl+O, Enter, Ctrl+X). Next, handle legacy logs. Type sudo nano /etc/logrotate.conf. Look for the line that dictates global rotation, usually rotate 4 (meaning keep 4 weeks). Change this to a massive number, like rotate 520 (keep 10 years). Save and exit. Finally, restart the journal service by typing sudo systemctl restart systemd-journald.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.