Why Systemd’s Journal Logs Are Binary (and Why That’s Not as Evil as It Sounds)
If you’ve ever poked around a modern Linux system and typed ls /var/log/journal , you’ve probably been greeted by a pile of opaque .journal files instead of the familiar plain-text logs you’ve known for decades. Open one in less or cat and you get garbage. Many long-time Unix users react with mild horror: “What happened to the sacred tradition of human-readable text files?” This post explains the deliberate design decision behind systemd’s journal , the philosophy that drove it, and how it compares to the classic files in /var/log. The Classic Unix Way: Text Is King For most of Unix history, system logs lived as simple append-only text files: /var/log/messages /var/log/syslog /var/log/auth.log You could grep, tail -f, awk, zgrep across rotated files, or even open them in vi when things went wrong. The format was loosely structured at best: a timestamp, a hostname, a program name, and a free-form message. Everything else was either missing or jammed into the text string in a...
