The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List loaded services | systemctl list-units --type=service | View examples |
| List installed unit files | systemctl list-unit-files --type=service | View examples |
| Inspect service status | systemctl status nginx.service | View examples |
| Test active state | systemctl is-active --quiet nginx.service | View examples |
| Read unit properties | systemctl show nginx.service \
--property=ActiveState,SubState,MainPID | View examples |
| Show unit source | systemctl cat nginx.service | View examples |
| Show dependencies | systemctl list-dependencies nginx.service | View examples |
| Start a service | sudo systemctl start nginx.service | View examples |
| Stop a service | sudo systemctl stop nginx.service | View examples |
| Restart a service | sudo systemctl restart nginx.service | View examples |
| Reload service configuration | sudo systemctl reload nginx.service | View examples |
| Enable and start | sudo systemctl enable --now nginx.service | View examples |
| Disable and stop | sudo systemctl disable --now nginx.service | View examples |
| Reload unit definitions | sudo systemctl daemon-reload | View examples |
| Create a drop-in override | sudo systemctl edit nginx.service | View examples |
| Read one unit's journal | journalctl --unit=nginx.service --no-pager | View examples |
| Limit to current boot | journalctl --boot=0 | View examples |
| Read previous boot | journalctl --boot=-1 | View examples |
| Filter by time | journalctl --since='1 hour ago' --until=now | View examples |
| Filter error priorities | journalctl --priority=err --boot=0 | View examples |
| Follow a unit live | journalctl --follow --unit=nginx.service | View examples |
| Emit JSON records | journalctl --unit=nginx.service --output=json --lines=20 | View examples |
| Read kernel messages | journalctl --dmesg --boot=0 | View examples |
Diagnose before changing service state: inspect the unit definition, active state, dependencies, and recent journal together. Use exact unit names, distinguish starting now from enabling at boot, and treat reload, restart, daemon-reload, and reboot as different operations.
Step by step
Detailed examples
Distinguish loaded units from installed unit files
list-units describes units currently loaded into the manager and defaults to active, pending, or failed units unless --all is added. list-unit-files reports installed definitions and enablement states such as enabled, disabled, static, masked, or generated. A static unit can still start through dependencies even though it cannot be enabled directly.
systemctl list-units --type=service --state=running
systemctl list-unit-files --type=service | head # The first view is runtime state; the second is installed enablement state.Correlate state, definition, and dependencies
status is a human-oriented snapshot with recent journal lines. is-active is better for scripts because its exit status communicates state, while show exposes stable property names. cat reveals the fragment and drop-ins the manager loaded; list-dependencies helps explain activation relationships but does not by itself show every ordering edge.
systemctl status nginx.service --no-pager
systemctl show nginx.service --property=LoadState,ActiveState,SubState,MainPID,ExecMainStatus
systemctl cat nginx.service
systemctl list-dependencies nginx.service # Unit-specific state and paths vary by system.Choose start, stop, restart, or reload precisely
start and stop change current runtime state only. restart performs stop and start and may interrupt requests; reload asks the service to reread its own configuration only when the unit supports that action. Check configuration with the service's native validation command, review impact, then inspect status and logs after an authorized change.
sudo nginx -t
sudo systemctl reload nginx.service
systemctl status nginx.service --no-pager
journalctl --unit=nginx.service --since='5 minutes ago' --no-pager # Proceed with reload only after validation succeeds.Separate boot enablement from runtime state
enable creates the relationships described by a unit's [Install] section but does not start it unless --now is present. disable removes those links but does not stop a running unit unless --now is present. Masking is stronger and blocks activation through dependencies as well as manual starts; use it only when that policy is intended.
systemctl is-enabled nginx.service
sudo systemctl enable --now nginx.service
systemctl is-enabled nginx.service
systemctl is-active nginx.service # Expected final states are enabled and active when the operation succeeds.Use drop-ins and reload manager configuration
systemctl edit creates an override under /etc rather than modifying a package-owned unit. After unit files change, daemon-reload makes the manager reread definitions; it does not restart affected services or reload their application configuration. Review the merged definition with systemctl cat and explicitly restart only when required.
sudo systemctl edit nginx.service
sudo systemctl daemon-reload
systemctl cat nginx.service
systemctl show nginx.service --property=FragmentPath,DropInPaths
# Restart separately only if the reviewed change requires it. # The editor and resulting paths depend on the system configuration.Narrow journal queries at the source
journalctl reads only records the current user is permitted to access. Combine --unit, --boot, --since, --until, and --priority so filtering occurs inside the journal reader rather than after a huge unbounded query. Boot history depends on retained journals, and a single priority includes that level and all more severe levels.
journalctl --unit=nginx.service \
--boot=0 \
--since='1 hour ago' \
--priority=err \
--no-pager # Zero or more matching journal records are printed.journalctl --list-boots
journalctl --boot=0 --lines=20 --no-pager
journalctl --boot=-1 --lines=20 --no-pager # Previous-boot output requires persistent or otherwise retained journal data.Follow live records or preserve structured fields
--follow waits for appended entries and is interactive until interrupted. JSON output preserves journal fields for tools, while the default short format is easier for people. Kernel messages are selected with --dmesg or -k. Logs can contain credentials, request data, internal addresses, and personal information, so redact before sharing.
journalctl --unit=nginx.service --lines=20 --output=json --no-pager
journalctl --dmesg --boot=0 --priority=warning --no-pager # JSON mode emits one structured journal entry per line.journalctl --follow --unit=nginx.service # Press Ctrl+C to stop following new records.Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- systemd projectsystemctl — Control the systemd system and service managerfreedesktop.org
- systemd projectjournalctl — Print log entries from the systemd journalfreedesktop.org
- systemd projectsystemd.unit — Unit configurationfreedesktop.org
- systemd projectsystemd.service — Service unit configurationfreedesktop.org
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



