After an unexplained reboot you run `journalctl -b -1` and are told that no persistent journal was found, although the current boot's messages are readable. What makes the previous boot's messages available in future?
LPIC-1 Exam 101-500, objective 101. System architecture hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct Create /var/log/journal (or set Storage=persistent in /etc/systemd/journald.conf) and restart systemd-journald
Correct. With the default Storage=auto, journald writes to disk only if /var/log/journal already exists; otherwise it keeps the journal in /run/log/journal, which is tmpfs and is emptied at every boot.
Not correct Raise SystemMaxUse in /etc/systemd/journald.conf
Wrong. SystemMaxUse caps how much disk space the persistent journal may occupy. It has no effect while no persistent journal is being written at all.
Not correct Run `journalctl --vacuum-time=2weeks` to stop old boots being discarded
Wrong, and backwards. The vacuum options delete journal files that are older or larger than a given bound; they only ever remove data.
Not correct Install and enable rsyslog so that the journal is forwarded to /var/log/messages
Wrong for the question asked. Forwarding to a syslog daemon does give you plain-text files that survive a reboot, but it does not create a journal, so journalctl -b -1 still has no previous boot to offer.
Why
journald's Storage setting decides where records go: volatile means /run/log/journal only, persistent means /var/log/journal and creates the directory, and the default auto means persistent only if that directory already exists. Because /run is a tmpfs, a volatile journal cannot outlive the boot that wrote it, which is why boot offsets such as -b -1 fail on an otherwise healthy system. Once persistence is in place, `journalctl --list-boots` enumerates the boots the journal still holds and each gets its own boot ID.
Where this comes from
- Cited
- manual page journald.conf(5)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 101 and space the ones you get wrong.
More questions on this objective
- You have a module file for a network driver on disk but the driver is not loaded. Which command reports the module's description, license, its dependencies and the parameters it accepts, without loading it into the kernel? machine-checked
- A module was loaded together with several modules it depends on. Which command unloads that module and then also unloads the dependencies that are left with a use count of zero? machine-checked
- You are filing a hardware bug report and the maintainer asks for the raw PCI vendor and device ID numbers rather than the human-readable names lspci normally prints. Which lspci option produces the numeric IDs? machine-checked
- A USB device is not getting the device node you expect. You want to watch, live, the kernel uevents and the resulting udev events as you unplug and replug it. Which command does that? machine-checked
- On a traditional BIOS PC, the firmware has completed its power-on self test and selected the hard disk as the boot device. What happens next? machine-checked
- A systemd-based machine fails during a normal boot because a service hangs. At the boot loader menu you want to edit the kernel command line for this one boot so the system comes up in single-user rescue mode instead. Which parameter do you append? machine-checked