/var/log/journal on a busy server has grown to several gigabytes. You want to reclaim space now by discarding archived journal data older than 30 days, without stopping journald. Which command does that?

LPIC-1 Exam 102-500, objective 108. Essential system services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct journalctl --vacuum-time=30d

Correct. It removes archived journal files whose newest entry is older than the given age, and reports how much was freed.

Not correct journalctl --rotate

Wrong on its own. --rotate asks journald to close the active files and start new ones. Nothing is deleted, although it is often run first so that recent data becomes eligible for a vacuum.

Not correct journalctl --flush

Wrong. --flush moves entries from the volatile journal in /run/log/journal into the persistent one under /var/log/journal. It increases the space used there rather than reclaiming it.

Not correct journalctl --vacuum-files=30

Wrong criterion. That is a real option, but it keeps at most 30 journal files irrespective of their age, which on a busy host can be a few hours of data or a year of it.

Why

The three vacuum options select by age, by total size and by file count: --vacuum-time, --vacuum-size and --vacuum-files. All of them act on archived files only, never on the journal file currently being written, which is why a --rotate beforehand sometimes frees more. For a standing limit rather than a one-off clean-up, set SystemMaxUse or MaxRetentionSec in /etc/systemd/journald.conf.

Where this comes from

Cited
manual page journalctl(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Essential system services

Practise LPIC-1 Exam 102-500