Check journald-usage¶
Overview¶
Checks the current disk usage of all systemd journal files (archived and active combined) and alerts when journal disk usage exceeds a configurable threshold.
Important Notes:
- From
man journald.conf:SystemMaxUse=andRuntimeMaxUse=control how much disk space the journal may use at most.SystemKeepFree=andRuntimeKeepFree=control how much disk space systemd-journald shall leave free for other uses. systemd-journald respects both limits and uses the smaller of the two values. The defaults are 10% and 15% of the file system size, capped to 4G each. Only archived files are deleted during vacuuming, so actual usage may exceed the configured limits.
Data Collection:
- Executes
journalctl --disk-usageto obtain the total disk usage of all archived and active journal files - Reads the effective journald configuration via
systemd-analyze cat-config systemd/journald.confto report the currentSystemMaxUseandSystemKeepFreevalues - Requires root or sudo privileges to access journal data
Fact Sheet¶
| Fact | Value |
|---|---|
| Check Plugin Download | https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/journald-usage |
| Nagios/Icinga Check Name | check_journald_usage |
| Check Interval Recommendation | Every minute |
| Can be called without parameters | Yes |
| Runs on | Linux |
| Compiled for Windows | No |
Help¶
usage: journald-usage [-h] [-V] [--always-ok] [--no-perfdata] [-w WARN]
Checks the current disk usage of all systemd journal files (archived and
active combined). Alerts when journal disk usage exceeds the configured
thresholds. Requires root or sudo.
options:
-h, --help show this help message and exit
-V, --version show program's version number and exit
--always-ok Always returns OK.
--no-perfdata Suppress the performance data section from the output.
The status message and the exit code are unaffected, so
alerting keeps working while trending data is dropped.
-w, --warning WARN WARN threshold in GiB. Default: >= 6
Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/journald-usage/
Usage Examples¶
./journald-usage --warning=500
Output:
3.0GiB used [WARNING] (sum of all archived and active journal files; SystemMaxUse=595M SystemKeepFree=1388M).
Configure `SystemMaxUse` and `SystemKeepFree` in `/etc/systemd/journald.conf/`, or remove the oldest archived
journal files by using `journalctl --vacuum-size=`, `--vacuum-time=` and/or `--vacuum-files=`.
States¶
- OK if the total journal disk usage is below
--warning(default: 6 GiB). - WARN if the total journal disk usage is >=
--warning(default: 6 GiB). - UNKNOWN if the account running the check may not read the journal, or only the part of it that belongs to the account itself.
--always-oksuppresses all alerts and always returns OK.
Perfdata / Metrics¶
| Name | Type | Description |
|---|---|---|
| journald-usage | Bytes | Total size of all archived and active journal files. |
Troubleshooting¶
Not allowed to read the systemd journal¶
Not allowed to read the systemd journal. Run this plugin as root or via sudo, or add the account running it to the `systemd-journal` group.
journalctl could not open a single journal file with the rights of the account running the check. Run the check via sudo (the shipped sudoers file allows it), or add the account to the systemd-journal group, which may read the whole journal: sudo usermod --append --groups systemd-journal icinga.
Not allowed to read the whole systemd journal¶
Not allowed to read the whole systemd journal, only the part that belongs to the account running this plugin. Run this plugin as root or via sudo, or add the account running it to the `systemd-journal` group.
journalctl showed the account running the check its own journal, but not the system journal and not the journals of other users. The disk usage of that part would be far too low, so the check refuses to answer instead. The fix is the same as above: run the check via sudo, or add the account to the systemd-journal group with sudo usermod --append --groups systemd-journal icinga.
Credits, License¶
- Authors: Linuxfabrik GmbH, Zurich
- License: The Unlicense, see LICENSE file.