Skip to content

Check journald-usage

Overview

Checks the current disk usage of all systemd journal files (archived and active combined) and alerts when journal disk usage exceeds a configurable threshold.

Important Notes:

  • From man journald.conf: SystemMaxUse= and RuntimeMaxUse= control how much disk space the journal may use at most. SystemKeepFree= and RuntimeKeepFree= control how much disk space systemd-journald shall leave free for other uses. systemd-journald respects both limits and uses the smaller of the two values. The defaults are 10% and 15% of the file system size, capped to 4G each. Only archived files are deleted during vacuuming, so actual usage may exceed the configured limits.

Data Collection:

  • Executes journalctl --disk-usage to obtain the total disk usage of all archived and active journal files
  • Reads the effective journald configuration via systemd-analyze cat-config systemd/journald.conf to report the current SystemMaxUse and SystemKeepFree values
  • Requires root or sudo privileges to access journal data

Fact Sheet

Fact Value
Check Plugin Download https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/journald-usage
Nagios/Icinga Check Name check_journald_usage
Check Interval Recommendation Every minute
Can be called without parameters Yes
Runs on Linux
Compiled for Windows No

Help

usage: journald-usage [-h] [-V] [--always-ok] [--no-perfdata] [-w WARN]

Checks the current disk usage of all systemd journal files (archived and
active combined). Alerts when journal disk usage exceeds the configured
thresholds. Requires root or sudo.

options:
  -h, --help          show this help message and exit
  -V, --version       show program's version number and exit
  --always-ok         Always returns OK.
  --no-perfdata       Suppress the performance data section from the output.
                      The status message and the exit code are unaffected, so
                      alerting keeps working while trending data is dropped.
  -w, --warning WARN  WARN threshold in GiB. Default: >= 6

Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/journald-usage/

Usage Examples

./journald-usage --warning=500

Output:

3.0GiB used [WARNING] (sum of all archived and active journal files; SystemMaxUse=595M SystemKeepFree=1388M).
Configure `SystemMaxUse` and `SystemKeepFree` in `/etc/systemd/journald.conf/`, or remove the oldest archived
journal files by using `journalctl --vacuum-size=`, `--vacuum-time=` and/or `--vacuum-files=`.

States

  • OK if the total journal disk usage is below --warning (default: 6 GiB).
  • WARN if the total journal disk usage is >= --warning (default: 6 GiB).
  • UNKNOWN if the account running the check may not read the journal, or only the part of it that belongs to the account itself.
  • --always-ok suppresses all alerts and always returns OK.

Perfdata / Metrics

Name Type Description
journald-usage Bytes Total size of all archived and active journal files.

Troubleshooting

Not allowed to read the systemd journal

Not allowed to read the systemd journal. Run this plugin as root or via sudo, or add the account running it to the `systemd-journal` group.

journalctl could not open a single journal file with the rights of the account running the check. Run the check via sudo (the shipped sudoers file allows it), or add the account to the systemd-journal group, which may read the whole journal: sudo usermod --append --groups systemd-journal icinga.

Not allowed to read the whole systemd journal

Not allowed to read the whole systemd journal, only the part that belongs to the account running this plugin. Run this plugin as root or via sudo, or add the account running it to the `systemd-journal` group.

journalctl showed the account running the check its own journal, but not the system journal and not the journals of other users. The disk usage of that part would be far too low, so the check refuses to answer instead. The fix is the same as above: run the check via sudo, or add the account to the systemd-journal group with sudo usermod --append --groups systemd-journal icinga.

Credits, License