How I stopped a 16‑GB microSD Raspberry Pi from dying mid‑boot because /var/log grew to 10 GB after a year of unattended cron jobs

Raspberry Pi’s are perfect for low‑power tinkering, but a 16‑GB microSD can start biting back if something writes too much data. After a year of unattended cron jobs, my Pi’s /var/log ballooned to 10 GB and the boot process stalled. Below is the exact walk‑through I used to bring the system back online and prevent a repeat.

Why the logs ate the SD card

The default Raspberry Pi OS ships with systemd‑journald for kernel and service logs and rsyslog for the classic syslog files. Both dump their output into /var/log. If you run cron jobs that spit out text and you don’t redirect or limit that output, each run just appends. Over a year, even a few megabytes per job can turn into gigabytes. The SD card’s limited write endurance means a bloated log file can accelerate wear‑out.

Quick diagnosis

Boot the Pi in recovery mode (hold Shift during boot to get the NOOBS menu, then choose “Recovery”). Mount the root filesystem read‑write:

sudo mount -o remount,rw /

Check overall usage:

df -h /

Typical output:

Filesystem      Size  Used Avail Use% Mounted on
/dev/mmcblk0p2   15G  10G  4.5G  67% /

Now drill into /var/log:

sudo du -sh /var/log

If it reports ~10 GB, the logs are the culprit. List the biggest files:

sudo ls -lhS /var/log | head

You’ll probably see journal or syslog. For a quick cleanup, truncate the journal:

sudo journalctl --vacuum-size=100M

This keeps the last 100 MB of journal entries. For syslog, truncate manually:

sudo truncate -s 0 /var/log/syslog

Reboot:

sudo reboot

If the Pi boots, the immediate problem is solved. If it still stalls, the filesystem may be corrupted or the SD card is failing. Run a filesystem check:

sudo fsck -f /dev/mmcblk0p2

Follow the prompts to repair.

Permanent fixes

1. Configure journald to limit disk usage

Edit /etc/systemd/journald.conf:

sudo nano /etc/systemd/journald.conf

Uncomment and set:

SystemMaxUse=200M
SystemKeepFree=100M
SystemMaxFileSize=50M

SystemMaxUse caps the total journal size; SystemKeepFree reserves free space for the system; SystemMaxFileSize limits individual journal files. After saving, restart journald:

sudo systemctl restart systemd-journald

Documentation: https://systemd.io/JOURNALD/

2. Set up logrotate for rsyslog

logrotate is already installed on Raspberry Pi OS. Create a custom rule for cron logs:

sudo nano /etc/logrotate.d/cron

Add:

/var/log/cron.log {
    daily
    rotate 7
    compress
    missingok
    notifempty
    create 0640 root adm
}

This keeps a week’s worth of compressed logs. For rsyslog’s main log, edit /etc/logrotate.d/rsyslog:

/var/log/syslog {
    daily
    rotate 7
    compress
    delaycompress
    missingok
    notifempty
    create 0640 root adm
}

Run logrotate -d /etc/logrotate.conf to test.

3. Use a tmpfs for transient logs

If you’re okay with logs disappearing on reboot, mount /var/log as a tmpfs:

sudo nano /etc/fstab

Add:

tmpfs   /var/log   tmpfs   defaults,noatime,mode=0755   0   0

This keeps logs in RAM, freeing the SD card. Be mindful of RAM usage; a 512 MB Pi may struggle if logs are large.

4. Separate log storage

If you want persistence but not on the main SD card, add a second microSD or USB drive. Create a partition, format it, and mount it somewhere like /mnt/logs. Then symlink /var/log into that mount or configure rsyslog to write directly to the new location.

sudo mkdir /mnt/logs
sudo mount /dev/sdb1 /mnt/logs
sudo ln -s /mnt/logs/syslog /var/log/syslog

Replace /dev/sdb1 with the correct device name.


TAGS: linux, raspberry-pi, logs, troubleshooting


See also