Throughout its operation, a Linux server records a very large number of settings, pieces of information and events, which are written to files: these are your server's logs.

On the vast majority of Linux OSes, these log files are stored in the /var/log folder:

total 2564
-rw-r--r-- 1 root root   15071 Aug  8 17:24 alternatives.log
drwxr-xr-x 2 root root    4096 Aug  9 08:55 apt
-rw-r----- 1 root adm   876834 Aug  9 09:54 auth.log
-rw------- 1 root utmp 1175040 Aug  9 09:54 btmp
-rw-r----- 1 root adm    68367 Aug  9 09:13 daemon.log
-rw-r--r-- 1 root root  320780 Aug  9 08:55 dpkg.log
-rw-r----- 1 root adm    19690 Aug  9 09:54 fail2ban.log
-rw-r--r-- 1 root root    3456 Dec 12  2017 faillog
-rw-r----- 1 root adm     2907 Jan 24  2018 kern.log
-rw-r--r-- 1 root root     292 Aug  9 08:48 lastlog
-rw-r----- 1 root adm     1100 Aug  8 17:23 mail.info
-rw-r----- 1 root adm     1100 Aug  8 17:23 mail.log
-rw-r----- 1 root adm     3334 May 26 15:58 messages
-rw-r--r-- 1 root root    75153 Aug  9 09:39 syslog
-rw-rw-r-- 1 root utmp   14976 Aug  9 08:48 wtmp

Each file corresponds to a different type of service. Some are very explicit (mail.log corresponds to the logs of the emails managed by your server), and others a little less so.

The main log files#

Here is a list of some of the log files you may find on a Linux server:

  • auth.log: corresponds to the authentication logs on your server (most often SSH). You will find information there about connection attempts to your VPS, the reasons they were refused and the history of connections made.
  • kern.log: corresponds to your kernel's logs. It contains the latest events recorded by the kernel. These may be various pieces of information about its usual operation (network card startup, system boot), as well as errors encountered.
  • mail.log: as its name suggests, it corresponds to the logs of the emails processed by your VPS. It is very useful to check it, especially if support reports an email spam problem to you.
  • apt/history.log: contains the history of changes made via APT (installing/uninstalling software, for example).
  • fail2ban.log: if you have installed and configured Fail2ban (over here), it contains the history of IP detections and bans on your VPS.
  • syslog: this is a bit of a catch-all file. You will find the general logs of your system there. It contains a lot of essential information, such as operations performed on the various services, runtime errors encountered, faults detected by the system, etc.

Good to know#

Each log file is different, so there is no universal methodology for handling them. However, several things are worth knowing:

  • The most recent logs are always added at the end of the file. The oldest ones are therefore at the top of the file.
  • The logging system regularly does some "housekeeping" in the logs: it creates new empty files, and saves the old ones in compressed format (.gz) to use less disk space. These are kept for several days.
  • Log files are not essential to your system (it can run without them). If you happen to run out of disk space on your server, a little cleanup in the logs can help you free up some space.

Viewing logs with systemd-journald#

On recent distributions such as Debian 13 and Ubuntu 26.04, some of the journals are also managed by systemd via the journalctl tool. This lets you view system events without going directly through the files in the /var/log folder:

root@HelpDesk:~# journalctl -f
root@HelpDesk:~# journalctl -u ssh

The first command displays the journals in real time, while the second restricts the display to the SSH service.

Useful commands#

View the contents of a log file live (real time)#

root@HelpDesk:/var/log# tail -f monfichier.log

Search within a log file#

root@HelpDesk:/var/log# grep "mot-clef" monfichier.log

List the latest SSH connections#

root@HelpDesk:/var/log# grep "Accepted" auth.log