Да неее)
Я имел ввиду вывод journalctl без аргументов)
Всё, что есть
[root@os-controller-01 keystone]# journalctl | grep keystone
Sep 19 10:36:48 os-controller-01 groupadd[293588]: group added to /etc/group: name=keystone, GID=163
Sep 19 10:36:48 os-controller-01 groupadd[293588]: group added to /etc/gshadow: name=keystone
Sep 19 10:36:49 os-controller-01 groupadd[293588]: new group: name=keystone, GID=163
Sep 19 10:36:49 os-controller-01 useradd[293595]: new user: name=keystone, UID=163, GID=163, home=/var/lib/keystone, shell=/sbin/nologin
Sep 19 10:55:27 os-controller-01 su[294993]: (to keystone) root on pts/0
Sep 19 10:55:27 os-controller-01 su[294993]: pam_unix(su:session): session opened for user keystone by root(uid=0)
Sep 19 10:55:29 os-controller-01 su[294993]: pam_unix(su:session): session closed for user keystone
Sep 19 11:18:54 os-controller-01 su[296677]: (to keystone) root on pts/0
Sep 19 11:18:54 os-controller-01 su[296677]: pam_unix(su:session): session opened for user keystone by root(uid=0)
Sep 19 11:18:55 os-controller-01 su[296677]: pam_unix(su:session): session closed for user keystone