A server crashed and has since rebooted. You want the journal entries of severity error and above from the boot before the current one. Which command retrieves them?
LPIC-1 Exam 102-500, objective 108. Essential system services hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct journalctl -f -p err
Wrong. -f follows the journal from the present moment forward, so it shows entries that have not happened yet, not the previous boot.
Not correct journalctl --since err -b
Wrong on both counts. --since takes a time, not a severity, and -b without an offset selects the current boot rather than the previous one.
Correct journalctl -b -1 -p err
Correct. -b -1 selects the boot immediately before the current one, and -p err limits output to severity err and the more urgent levels crit, alert and emerg.
Not correct journalctl -u -1 -p 3
Wrong. -u expects a unit name, so it would consume -1 as the unit. The -p 3 part is fine on its own, since 3 is the numeric form of err.
Why
-b with no argument means the current boot; -b -1 the previous one, -b -2 the one before that, and `journalctl --list-boots` prints the identifiers of the boots the journal still holds. This only works if the journal is persistent — a volatile journal in /run/log/journal is lost at every reboot, so the previous boot simply is not there. -p accepts either the syslog level name or its number (0 emerg through 7 debug) and always means 'this level and more urgent'.
Where this comes from
- Cited
- LPI exam objective 108.2
- What it says
- Filter journal output by boot and by priority.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.
More questions on this objective
- You corrected the running system's clock with `date -s`, but after the next power cycle the machine came back with the old wrong time. Which command copies the corrected system clock into the hardware (RTC) clock? machine-checked
- On a systemd-based distribution, which file determines the local time zone used by the C library when formatting times? machine-checked
- A host runs chrony as its NTP client. Which command shows the list of time sources chrony is currently talking to and how it rates each one? machine-checked
- In /etc/ntp.conf you find the line `server 0.pool.ntp.org iburst`. What does the `iburst` keyword do? machine-checked
- A minimal systemd host synchronises its clock with systemd-timesyncd. Which statement about that service is accurate? machine-checked
- On a systemd host, type the single command that turns on automatic network time synchronisation (do not include a path). machine-checked