An incident happened between 09:00 and 10:00 this morning and you want the journal entries from exactly that window, with nothing from before or after. Which command restricts the output that way?
LPIC-1 Exam 102-500, objective 108. Essential system services easy
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct journalctl --since 09:00 --until 10:00
Correct. --since and --until (short forms -S and -U) bound the output by timestamp; a bare HH:MM is taken as that time today.
Not correct journalctl -b -1
Wrong. -b selects entries by boot: -b -1 is everything from the previous boot, however long ago that was and however long it lasted.
Not correct journalctl -n 60
Wrong. -n prints the last N entries, defaulting to ten. Sixty entries have no relation to sixty minutes of wall-clock time.
Not correct journalctl --list-boots
Wrong. That prints one line per recorded boot with its identifier and the times it spanned. It lists boots, not log entries.
Why
Both options accept the full form YYYY-MM-DD HH:MM:SS, the keywords yesterday, today, tomorrow and now, and relative expressions such as "-1h" or "2 days ago"; quote any value that contains a space. Time filters combine with the other filters rather than replacing them, so `journalctl -u nginx.service --since 09:00 -p err` narrows by unit, time and priority at once.
Where this comes from
- Cited
- manual page journalctl(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.
More questions on this objective
- You corrected the running system's clock with `date -s`, but after the next power cycle the machine came back with the old wrong time. Which command copies the corrected system clock into the hardware (RTC) clock? machine-checked
- On a systemd-based distribution, which file determines the local time zone used by the C library when formatting times? machine-checked
- A host runs chrony as its NTP client. Which command shows the list of time sources chrony is currently talking to and how it rates each one? machine-checked
- In /etc/ntp.conf you find the line `server 0.pool.ntp.org iburst`. What does the `iburst` keyword do? machine-checked
- A minimal systemd host synchronises its clock with systemd-timesyncd. Which statement about that service is accurate? machine-checked
- On a systemd host, type the single command that turns on automatic network time synchronisation (do not include a path). machine-checked