# 0. can you actually see the system's evidence, or only your own? id | grep -o 'adm\|systemd-journal' || echo "unprivileged view -- use sudo" # 1. volume first, at warning, not just err sudo journalctl -b -p err --no-pager -q | wc -l sudo journalctl -b -p warning --no-pager -q | wc -l # 2. collapse a thousand lines into distinct problems sudo journalctl -b -p warning --no-pager -q -o cat \ | sed 's/[0-9a-f]\{8,\}/HEX/g; s/[0-9]\+/N/g' \ | sort | uniq -c | sort -rn | head -20 # 3. attribute by payload, not by _COMM sudo journalctl -b -q -o cat | grep "" \ | sed -E 's/^\(([a-zA-Z0-9_.-]+):[0-9]+\).*/\1/' | sort | uniq -c | sort -rn # 4. what is in the way of the desktop -- not what is slow systemd-analyze systemd-analyze critical-chain systemd-analyze blame | head -10 # 5. out-of-tree modules against every installed kernel sudo dkms status ; cat /proc/sys/kernel/tainted ; mokutil --sb-state # 6. what apt will actually serve you, priorities included apt-cache policy ; apt list --upgradable 2>/dev/null ; dpkg -l | grep '^rc' # 7. re-read the exact query that found it -- this is the step that confirms