Chapter 4: Linux Ops Refresh for DevOps
4.3 Logs — journalctl and tail -f
When a service fails, logs tell the story.
# systemd unit logs (common on modern Amazon Linux / Ubuntu)
sudo journalctl -u nginx -n 50 --no-pager
sudo journalctl -u nginx -f
# classic file logs
sudo tail -n 50 /var/log/messages
sudo tail -f /var/log/nginx/access.log
Why -f. Follow mode streams new lines while you curl the app in another terminal. You see the request arrive — or you see the error at the same second.
Steps — follow logs while you hit the app
- SSH into your practice VM (reuse an instance from the AWS course).
- In terminal A:
sudo journalctl -u <your-service> -forsudo tail -fon the access log you use. - In terminal B:
curl -I http://localhost(or your app port). - Watch terminal A — a new line should appear if the service handles the request.
- Stop follow with Ctrl+C when done.
What you see: either a healthy access/status line, or an error with a path and reason. Fix from the message; do not guess.
Link to AWS
Longer log paths, web server layout and SELinux notes belong in the AWS Linux and web-server chapters. Come back here for the DevOps habit: always watch logs while you reproduce.