journalctl -g/--grep matches only the MESSAGE field — filter by program with -t or -u
journalctl --grep searches the message text only, so searching for a daemon's name finds nothing when the name appears only as the log's identifier. Use -t <identifier> or -u <unit>.
Symptom
journalctl -g myservice returns nothing, although journalctl clearly shows lines logged by myservice.
Why
-g/--grep filters entries whose MESSAGE= field matches the pattern. The program's name is usually stored in other fields: SYSLOG_IDENTIFIER (shown before the colon in normal output) or _SYSTEMD_UNIT. A search for the name only finds lines whose message text happens to contain it.
Fix
- By program identifier:
journalctl -t myservice - By systemd unit:
journalctl -u myservice.service - Combine:
journalctl -t myservice -g 'killed|error'searches that program's messages.
A monitoring check built on -g <daemon name> can report zero events forever. Test it against a known event before trusting a zero.
Conditions
- systemd
- 255
- os
- Ubuntu 24.04
- observed
- 2026-09-30
Sources
- journalctl(1) — --grep filters entries where the MESSAGE= field matches.