Raspberry Pi’s are perfect for low‑power tinkering, but a 16‑GB microSD can start biting back if something writes too much data. After a year of unattended cron jobs, my Pi’s /var/log ballooned to 10 GB and the boot process stalled. Below is the exact walk‑through I used to bring the system back online and prevent a repeat.
Why the logs ate the SD card
The default Raspberry Pi OS ships with systemd‑journald for kernel and service logs and rsyslog for the classic syslog files. Both dump their output into /var/log. If you run cron jobs that spit out text and you don’t redirect or limit that output, each run just appends. Over a year, even a few megabytes per job can turn into gigabytes. The SD card’s limited write endurance means a bloated log file can accelerate wear‑out.
Quick diagnosis
Boot the Pi in recovery mode (hold Shift during boot to get the NOOBS menu, then choose “Recovery”). Mount the root filesystem read‑write:
sudo mount -o remount,rw /
Check overall usage:
df -h /
Typical output:
Filesystem Size Used Avail Use% Mounted on
/dev/mmcblk0p2 15G 10G 4.5G 67% /
Now drill into /var/log:
sudo du -sh /var/log
If it reports ~10 GB, the logs are the culprit. List the biggest files:
sudo ls -lhS /var/log | head
You’ll probably see journal or syslog. For a quick cleanup, truncate the journal:
sudo journalctl --vacuum-size=100M
This keeps the last 100 MB of journal entries. For syslog, truncate manually:
sudo truncate -s 0 /var/log/syslog
Reboot:
sudo reboot
If the Pi boots, the immediate problem is solved. If it still stalls, the filesystem may be corrupted or the SD card is failing. Run a filesystem check:
sudo fsck -f /dev/mmcblk0p2
Follow the prompts to repair.
Permanent fixes
1. Configure journald to limit disk usage
Edit /etc/systemd/journald.conf:
sudo nano /etc/systemd/journald.conf
Uncomment and set:
SystemMaxUse=200M
SystemKeepFree=100M
SystemMaxFileSize=50M
SystemMaxUse caps the total journal size; SystemKeepFree reserves free space for the system; SystemMaxFileSize limits individual journal files. After saving, restart journald:
sudo systemctl restart systemd-journald
Documentation: https://systemd.io/JOURNALD/
2. Set up logrotate for rsyslog
logrotate is already installed on Raspberry Pi OS. Create a custom rule for cron logs:
sudo nano /etc/logrotate.d/cron
Add:
/var/log/cron.log {
daily
rotate 7
compress
missingok
notifempty
create 0640 root adm
}
This keeps a week’s worth of compressed logs. For rsyslog’s main log, edit /etc/logrotate.d/rsyslog:
/var/log/syslog {
daily
rotate 7
compress
delaycompress
missingok
notifempty
create 0640 root adm
}
Run logrotate -d /etc/logrotate.conf to test.
3. Use a tmpfs for transient logs
If you’re okay with logs disappearing on reboot, mount /var/log as a tmpfs:
sudo nano /etc/fstab
Add:
tmpfs /var/log tmpfs defaults,noatime,mode=0755 0 0
This keeps logs in RAM, freeing the SD card. Be mindful of RAM usage; a 512 MB Pi may struggle if logs are large.
4. Separate log storage
If you want persistence but not on the main SD card, add a second microSD or USB drive. Create a partition, format it, and mount it somewhere like /mnt/logs. Then symlink /var/log into that mount or configure rsyslog to write directly to the new location.
sudo mkdir /mnt/logs
sudo mount /dev/sdb1 /mnt/logs
sudo ln -s /mnt/logs/syslog /var/log/syslog
Replace /dev/sdb1 with the correct device name.
TAGS: linux, raspberry-pi, logs, troubleshooting
See also
- When my Raspberry Pi Home Server Ran Out of Space During a Midnight Backup, I Built a One‑Line Bash Alert Script to Save the Day.
- How a Forgotten SSH Key Stopped My Nightly Off‑Site Borg Backup and the Quick Fix I Implemented
- A tiny zsh function that lets you jump up any number of directories with one command
- Why my 4GB Raspberry Pi 4 keeps swapping during a Python script – and how I fixed it by moving swap to USB
- Rescuing a system that boots to emergency mode because /boot ran out of space