You want to watch new log entries for the sshd service as they arrive, on a systemd host. Which command does exactly that?

LPIC-1 Exam 102-500, objective 108. Essential system services medium

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct journalctl -b sshd

Wrong. -b restricts output to a boot, not to a unit, and its optional argument is a boot id or offset. The trailing `sshd` is left as a positional argument, where journalctl expects a field match or a path to an executable, so the command errors out instead of following the service.

Correct journalctl -u sshd -f

Correct. -u (--unit) filters to the messages of one systemd unit and -f (--follow) keeps the command running and prints new entries as they are written, like tail -f.

Not correct journalctl -p sshd

Wrong. -p (--priority) filters by syslog severity and expects a level such as err or 3, not a unit name.

Not correct journalctl --since sshd

Wrong. --since expects a timestamp or a phrase such as "today" or "1 hour ago". It selects a time window, not a service.

Why

The journalctl filters most worth memorising: -u UNIT for one systemd unit, -f to follow live, -b for the current boot (-b -1 for the previous one), -p LEVEL for a severity and everything more urgent, -n N for the last N lines, --since and --until for a time window, and -k for kernel messages only. They combine freely, so `journalctl -u nginx -b -p err` is a legitimate query.

Where this comes from

Cited
LPI exam objective 108.2
What it says
Retrieve and filter journal entries with journalctl.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 108 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500