Lesson 29 / 31

Logs & Network Troubleshooting

Read system logs with journalctl and /var/log, and inspect addresses and listening ports with ip and ss.

Reading logs

On systemd distros journalctl reads the journal; classic text logs live in /var/log.

journalctl -u nginx --since "1 hour ago"
journalctl -p err -b           # errors since boot
tail -f /var/log/syslog

Network tools

ip shows interfaces and routes; ss shows sockets and the processes listening on ports.

ip addr show
ip route
ss -tulpn          # listening TCP/UDP ports with processes
curl -I https://example.com

When a service fails, check systemctl status, then its journal, then the port with ss. Work from the service outward.