Collect Linux Journal Evidence From the Boot Where the Problem Happened
After restarting a Linux computer, the most recent messages may describe the new session rather than the failure you want investigated. A useful journal extract identifies the correct boot and the time around the event before narrowing the records further.
Match the recorded session
Write down the approximate failure time, what you were doing and whether you restarted normally or the machine restarted unexpectedly. Include the local time zone. Run journalctl --list-boots and compare the first and last recorded message times for each available boot with that note. These are journal coverage times, not necessarily the exact startup and shutdown times.
Use the boot identifier or appropriate offset from the list. For example, journalctl -b -1 selects the previous available boot in the normal local journal view. Do not assume it contains yesterday's incident if several restarts happened afterwards; select using the displayed times.
If the relevant boot is absent, record that limitation. Journal retention, persistent logging settings and access permissions affect what is available. An empty or restricted result is not evidence that the computer experienced no problem.
Reduce the extract without losing context
Add --since and --until with a small time window around the incident. Use complete quoted dates and times where possible. The --output=short-full format includes fuller timestamp context, while --no-pager avoids having a terminal pager hide the ends of long lines in copied output.
Ask an authorised administrator to obtain system-level records if your account cannot read them. Avoid changing group memberships just to make a one-off support collection convenient. Keep the chosen boot, time window and any permission warning in the accompanying note.
Review the resulting text locally for account names, private paths, network addresses and application content before sharing it. Retain the unedited original privately so any necessary redaction does not destroy the diagnostic source.
Check that the first and last timestamps cover the intended event and that the selected boot matches the failure. Present the messages as observations; nearby warnings may provide leads without proving which one caused the restart.
Sources: Ubuntu documentation.