System Logs
Where Logs Live
When something goes wrong on Linux, the first instinct of every experienced admin is the same: go read the logs. Traditional text logs live under /var/log - recall from the Filesystems module that /var is specifically the directory the FHS reserves for data that's expected to keep growing throughout the system's life.
| File | Contents |
|---|---|
/var/log/syslog / messages | General system messages |
/var/log/auth.log / secure | Authentication & sudo |
/var/log/kern.log | Kernel messages |
/var/log/dmesg | Boot-time kernel ring buffer |
/var/log/boot.log | Boot service output |
Modern systemd-based distros additionally centralize logs in the journal you met in the Boot & systemd module (journalctl) - and many distros run both systems side by side, with the journal often being the more complete, structured source and the text files kept for compatibility with older tools and scripts.
$ sudo tail -f /var/log/auth.log
$ journalctl -u ssh --since '10 min ago'
Notice both commands are answering the same underlying question - "what has SSH been doing recently?" - just via two different logging systems. Being comfortable in both is important, because you won't always control which one a given server was set up to rely on.
Tip: The exact filenames differ by distro family, and it's worth knowing both names cold rather than guessing: Debian/Ubuntu usessyslogandauth.log; RHEL/Fedora usesmessagesandsecurefor the equivalent content. When a tutorial or exam question mentions one and you're on the other family, mentally substitute the matching name.