Nearly every server problem leaves a message in a log file: a failed login, a PHP fatal error, a database that couldn't start. Knowing where to look turns hours of guessing into minutes. Logs live in two places on modern Linux: the systemd journal (read with journalctl) and plain text files under /var/log.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
The systemd journal
Most services write to the journal. The most useful commands:
| What you want | Command |
|---|---|
| Logs for one service | sudo journalctl -u nginx |
| Only the last 50 lines | sudo journalctl -u mariadb -n 50 |
| Follow live (Ctrl+C to stop) | sudo journalctl -u php8.3-fpm -f |
| A time range | sudo journalctl --since "1 hour ago" or --since "2026-09-20 10:00" --until "2026-09-20 11:00" |
| Only errors since the last boot | sudo journalctl -p err -b |
| The previous boot (after a crash or reboot) | sudo journalctl -b -1 |
| Kernel messages (hardware, out of memory) | sudo journalctl -k or sudo dmesg -T |
Tip: after a failed systemctl start, systemctl status name shows the last few log lines directly.
If sudo journalctl --list-boots shows only the current boot, the journal is not kept across reboots. Make it persistent with sudo mkdir -p /var/log/journal && sudo systemctl restart systemd-journald.
Where each log lives
| Log | Ubuntu | Debian 12 | AlmaLinux / Rocky |
|---|---|---|---|
| SSH logins, sudo | /var/log/auth.log | journalctl -u ssh | /var/log/secure |
| General system | /var/log/syslog | journalctl | /var/log/messages |
| Nginx | /var/log/nginx/access.log and error.log | /var/log/nginx/access.log and error.log | /var/log/nginx/access.log and error.log |
| Apache | /var/log/apache2/ | /var/log/apache2/ | /var/log/httpd/ |
| PHP-FPM | /var/log/php8.3-fpm.log | /var/log/php8.2-fpm.log | /var/log/php-fpm/error.log, www-error.log |
| MariaDB | journalctl -u mariadb | journalctl -u mariadb | /var/log/mariadb/mariadb.log |
| Package installs and updates | /var/log/apt/history.log | /var/log/apt/history.log | /var/log/dnf.log, dnf history |
| Fail2ban | /var/log/fail2ban.log | /var/log/fail2ban.log | /var/log/fail2ban.log |
| Automatic updates | /var/log/unattended-upgrades/ | /var/log/unattended-upgrades/ | journalctl -u dnf-automatic |
Debian 12 does not install a traditional syslog daemon, so there is no /var/log/syslog or auth.log; use journalctl instead. PM2 apps log to ~/.pm2/logs/ (pm2 logs), and Docker containers to docker compose logs.
Reading text logs
sudo tail -n 100 /var/log/nginx/error.log # last 100 lines sudo tail -f /var/log/nginx/error.log # follow live sudo less +G /var/log/nginx/access.log # open at the end, q to quit sudo zgrep "example.com" /var/log/nginx/access.log.*.gz # search old compressed logs
Handy one-liners
Who tried to log in over SSH?
# Ubuntu sudo grep "Failed password" /var/log/auth.log | tail # Debian sudo journalctl -u ssh | grep "Failed" | tail # AlmaLinux / Rocky sudo grep "Failed password" /var/log/secure | tail # successful logins and reboots last -n 20
Which IPs hit your site the most?
sudo awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -nr | head
Which pages return server errors (5xx)?
sudo awk '$9 ~ /^5/ {print $9, $7}' /var/log/nginx/access.log | sort | uniq -c | sort -nr | head
AlmaLinux/Rocky: is SELinux blocking something?
sudo ausearch -m avc -ts recent
If you see denied lines mentioning nginx, httpd or php-fpm, fix the file labels (restorecon) or enable the matching boolean (for example httpd_can_network_connect) rather than turning SELinux off.
Log rotation
logrotate runs daily and compresses and removes old logs according to files in /etc/logrotate.d/. If a custom app writes its own log, add a small rule there so it doesn't grow forever. If your disk fills up with logs, see How to Monitor Your VPS and Fix a Full Disk.
Sending us a log
If you contact support about a VPS problem, include the relevant lines (not the whole file) and the time the problem happened. Remove passwords, API keys and customer personal data before sharing.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer