A systemd server with a persistent journal rebooted overnight. You need the log messages from the boot that ended in that reboot, not from the current boot. Which command shows them?

LPIC-1 Exam 101-500, objective 101. System architecture medium

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct dmesg

Wrong. dmesg prints the kernel ring buffer, which lives in memory and is emptied at every boot, so it can never show anything from a previous boot.

Not correct journalctl -b

Wrong. With no offset, -b limits output to the current boot, which is precisely the boot you want to exclude.

Correct journalctl -b -1

Correct. -b takes a boot offset: 0 (the default) is the current boot, -1 the previous one, -2 the one before that. journalctl --list-boots shows the offsets available.

Not correct journalctl -f

Wrong. -f follows the journal and prints new entries as they arrive, like tail -f. It shows the present, not the past.

Why

Boot-offset selection only works if the journal survives reboots. That requires persistent storage, normally Storage=persistent in /etc/systemd/journald.conf or simply the existence of /var/log/journal; with the default volatile setup the journal lives in /run/log/journal and is lost at reboot. For kernel-only messages add -k, which is the journal equivalent of dmesg but can be combined with a boot offset.

Where this comes from

Cited
LPI exam objective 101.2
What it says
Reviewing boot messages with dmesg and with the systemd journal.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 101 and space the ones you get wrong.

Practise LPIC-1 Exam 101-500