Linux who Command: List Logged-In Users

who shows the currently logged-in users, their terminals, and login times based on login records. It is useful for quickly checking active login sessions on servers where multiple users are connected.

What is the who command?

The basic output is mainly composed of the username, terminal device, and login time. If it is a remote connection, the host information may be displayed at the end. It is not a command that shows all running processes or the privileges of the current user.

Basic syntax

who [option]

The installed implementation and options may vary depending on the distribution. Check the current system's description with man who.

Examples

Viewing active login sessions

If the same user is logged in on multiple terminals, multiple lines may appear.

who

Display column headings

First, check the meaning of each output column.

who -H

Login User Summary

Displays the usernames and total session counts captured in the current login records.

who -q

Read one line of login session

who shows the sessions registered in the current login records. In the example, the user name, terminal, login time, and remote access location appear in order.

who

Example output (time and terminal display may vary depending on the environment):

alice pts/0 2026-09-28 09:00 (192.0.2.10)

If the same user is connected to multiple terminals, multiple lines may appear. Conversely, in containers or some non-interactive sessions, there may be no login records even if actual processes exist, resulting in empty output. To see the process activity of the current logged-in user, use w.

Main Options and Format

Options/Format Description
-H Displays the headers of the output columns.
-q Briefly displays login usernames and their total count.
-u Displays additional information such as idle time.
-b Displays the system's last boot time.

Precautions when using

who usually reads login records from the utmp series. In containers, minimal installation environments, or sessions that do not leave records, the output may be empty or partially visible even if the actual processes exist. To fully audit connection traces, service logs and authentication logs should also be checked.

Frequently Asked Questions

If who outputs nothing, does that mean there are no users?

Not necessarily. The current environment may not provide login records, so check both the terminal session and the system logs together.

Official Documentation

The exact behavior of the option and implementation differences can be found in the official documentation related to who.

More in This Category
Linux mount Command: Inspect and Mount Filesystems

Linux mount Command: Inspect and Mount Filesystems

Learn how to inspect and Mount Filesystems with the Linux mount command, including practical examples, key options, and important precautions.

Linux zypper Command: Manage Packages on openSUSE and SUSE

Linux zypper Command: Manage Packages on openSUSE and SUSE

Learn how to manage Packages on openSUSE and SUSE with the Linux zypper command, including practical examples, key options, and important precautions.

Linux clear Command: Clear the Terminal Display

Linux clear Command: Clear the Terminal Display

Learn how to use the Linux clear command to clear the visible terminal screen and understand scrollback behavior, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux mkdir Command: Create Directories and Parent Paths

Linux mkdir Command: Create Directories and Parent Paths

Learn how to create directories with Linux mkdir, build missing parent paths, set permissions, understand umask behavior, and verify results in scripts.

Linux stat Command: Display Detailed File Metadata

Linux stat Command: Display Detailed File Metadata

Learn how to use the Linux stat command to inspect file size, permissions, ownership, timestamps, inode, and filesystem metadata, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux awk Command: Analyze Text by Fields

Linux awk Command: Analyze Text by Fields

Learn how to analyze Text by Fields with the Linux awk command, including practical examples, key options, and important precautions.

Linux bunzip2 Command: Decompress bzip2 Files

Linux bunzip2 Command: Decompress bzip2 Files

Learn how to decompress bzip2 Files with the Linux bunzip2 command, including practical examples, key options, and important precautions.

Linux diff Command: Compare Text Files and Directories

Linux diff Command: Compare Text Files and Directories

Learn how Linux diff compares text files and directories, produces unified patches, ignores selected whitespace changes, and reports differences through exit status.

Linux uname Command: Check Kernel and System Architecture

Linux uname Command: Check Kernel and System Architecture

Learn how to check Kernel and System Architecture with the Linux uname command, including practical examples, key options, and important precautions.

Linux Tutorial / Choosing a Linux Distribution

Linux Tutorial / Choosing a Linux Distribution

Explore major Linux distributions and learn when to choose Ubuntu LTS or Rocky Linux for study and server practice. Compare package management, release policies, and practical selection criteria.