journalctl filters rather than greps: -u picks units (repeat it to merge), --since/--until take times or "1 hour ago", -p err that priority and worse, -b this boot, -g a regex, -f follows, -n 50 the last 50, and -o cat drops prefixes.
sudo journalctl -u apache2 -u mysql --since 13:36:10 --until 13:36:40
sudo journalctl -u mysql -p warning --since today
sudo tail -n 1 /var/log/mysql/error.log | cut -c 1-90Output
Sep 23 13:36:14 PHANG systemd[1]: Stopping apache2.service - The Apache HTTP Server... Sep 23 13:36:14 PHANG systemd[1]: Stopping mysql.service - MySQL Community Server... ... Sep 23 13:36:34 PHANG systemd[1]: Started apache2.service - The Apache HTTP Server. Sep 23 13:36:35 PHANG systemd[1]: Started mysql.service - MySQL Community Server. -- No entries -- 2026-09-23T05:36:35.437077Z 0 [System] [MY-010931] [Server] /usr/sbin/mysqld: ready for co
The merged view shows a restart's order, but MySQL 524 's warnings are not in the journal: it writes them to its own file, in UTC. Read Apache 129 's and MySQL's files for their errors; for timers and your own units (systemd Services), the journal is the log.