3 min read Sep 26, 2026

How to Read Server Logs on Your VPS

Find and read the logs that explain what went wrong on your VPS: journalctl, SSH logins, Nginx and Apache errors, PHP-FPM, MariaDB, package updates and SELinux denials.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

Nearly every server problem leaves a message in a log file: a failed login, a PHP fatal error, a database that couldn't start. Knowing where to look turns hours of guessing into minutes. Logs live in two places on modern Linux: the systemd journal (read with journalctl) and plain text files under /var/log.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

The systemd journal

Most services write to the journal. The most useful commands:

What you wantCommand
Logs for one servicesudo journalctl -u nginx
Only the last 50 linessudo journalctl -u mariadb -n 50
Follow live (Ctrl+C to stop)sudo journalctl -u php8.3-fpm -f
A time rangesudo journalctl --since "1 hour ago" or --since "2026-09-20 10:00" --until "2026-09-20 11:00"
Only errors since the last bootsudo journalctl -p err -b
The previous boot (after a crash or reboot)sudo journalctl -b -1
Kernel messages (hardware, out of memory)sudo journalctl -k or sudo dmesg -T

Tip: after a failed systemctl start, systemctl status name shows the last few log lines directly.

If sudo journalctl --list-boots shows only the current boot, the journal is not kept across reboots. Make it persistent with sudo mkdir -p /var/log/journal && sudo systemctl restart systemd-journald.

Where each log lives

LogUbuntuDebian 12AlmaLinux / Rocky
SSH logins, sudo/var/log/auth.logjournalctl -u ssh/var/log/secure
General system/var/log/syslogjournalctl/var/log/messages
Nginx/var/log/nginx/access.log and error.log/var/log/nginx/access.log and error.log/var/log/nginx/access.log and error.log
Apache/var/log/apache2//var/log/apache2//var/log/httpd/
PHP-FPM/var/log/php8.3-fpm.log/var/log/php8.2-fpm.log/var/log/php-fpm/error.log, www-error.log
MariaDBjournalctl -u mariadbjournalctl -u mariadb/var/log/mariadb/mariadb.log
Package installs and updates/var/log/apt/history.log/var/log/apt/history.log/var/log/dnf.log, dnf history
Fail2ban/var/log/fail2ban.log/var/log/fail2ban.log/var/log/fail2ban.log
Automatic updates/var/log/unattended-upgrades//var/log/unattended-upgrades/journalctl -u dnf-automatic

Debian 12 does not install a traditional syslog daemon, so there is no /var/log/syslog or auth.log; use journalctl instead. PM2 apps log to ~/.pm2/logs/ (pm2 logs), and Docker containers to docker compose logs.

Reading text logs

sudo tail -n 100 /var/log/nginx/error.log      # last 100 lines
sudo tail -f /var/log/nginx/error.log           # follow live
sudo less +G /var/log/nginx/access.log          # open at the end, q to quit
sudo zgrep "example.com" /var/log/nginx/access.log.*.gz   # search old compressed logs

Handy one-liners

Who tried to log in over SSH?

# Ubuntu
sudo grep "Failed password" /var/log/auth.log | tail
# Debian
sudo journalctl -u ssh | grep "Failed" | tail
# AlmaLinux / Rocky
sudo grep "Failed password" /var/log/secure | tail

# successful logins and reboots
last -n 20

Which IPs hit your site the most?

sudo awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -nr | head

Which pages return server errors (5xx)?

sudo awk '$9 ~ /^5/ {print $9, $7}' /var/log/nginx/access.log | sort | uniq -c | sort -nr | head

AlmaLinux/Rocky: is SELinux blocking something?

sudo ausearch -m avc -ts recent

If you see denied lines mentioning nginx, httpd or php-fpm, fix the file labels (restorecon) or enable the matching boolean (for example httpd_can_network_connect) rather than turning SELinux off.

Log rotation

logrotate runs daily and compresses and removes old logs according to files in /etc/logrotate.d/. If a custom app writes its own log, add a small rule there so it doesn't grow forever. If your disk fills up with logs, see How to Monitor Your VPS and Fix a Full Disk.

Sending us a log

If you contact support about a VPS problem, include the relevant lines (not the whole file) and the time the problem happened. Remove passwords, API keys and customer personal data before sharing.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer