Linux last Command: Review Login and Reboot History
last is a command that checks the system's login and logout history from the most recent record. By default, it reads /var/log/wtmp and shows the user, terminal, remote host, login time, logout time, and session duration.
It is useful for checking the login history of specific users or periods and for examining reboot or abnormal shutdown times. However, periods during which wtmp was not recorded or has been rotated or deleted cannot be queried, and security incidents should not be concluded based solely on this record.
What is the last command?
last searches the wtmp login records from the end and outputs the latest entries first. Typically, you can check the logged-in user's name, the terminal used (tty or pts), the host or IP address connected from, login and logout times, and session duration.
wtmp is not a text log but a file in a record format defined by the system. Therefore, it should be read with tools that understand the format, such as last, rather than cat or a text editor. Depending on the distribution and system settings, file location, whether it is recorded, and retention period may vary.
Basic syntax and reading the output
The basic syntax is as follows. If the username or terminal is omitted, it displays all available records.
last [option] [username|terminal...]
To check the most recent login records, execute as follows.
last
mina pts/1 192.0.2.24 Fri Sep 18 21:10 - 22:42 (01:31) alex tty1 Fri Sep 18 19:04 - 19:35 (00:31) reboot system boot 6.12.0 Fri Sep 18 18:58 still running
The first column is the user, the second column is the terminal, the third column is the remote host or kernel information, followed by the login time and logout status. Local console logins without a remote address may have an empty host column.
Frequently used last options
| Option | Function | Usage Examples |
|---|---|---|
-n N, --limit N |
Output up to N entries | last -n 20 |
-s time, --since time |
Show status after the specified time | last -s 2026-09-01 |
-t time, --until time |
Display status until the specified time | last -t 2026-09-19 |
-p time, --present time |
Display users connected at the specified time | last -p '2026-09-18 21:00' |
-F, --fulltimes |
Display complete date and time of login and logout | Detailed view without omitting the year |
--time-format iso |
Display in ISO 8601 format with time zone | Useful when comparing with records from other systems |
-i, --ip |
Display remote host as numeric IP | Check the recorded address instead of the DNS name |
-a, --hostlast |
Move the host field to the last column | Improve readability with long date output |
-R, --nohostname |
Hide the host field | Focus on local sessions and time |
-x, --system |
Also display shutdown and runlevel change records | Examine the state before and after reboot |
-f file, --file file |
Reading other wtmp files | last -f /var/log/wtmp.1 |
The names and supported scope of options may vary depending on the implementation of last. This article is based on the widely used util-linux implementation on Linux, and the latest definitions can be found on the official util-linux last manual page.
Filtering only the desired login records
Viewing records of a specific user
By adding a username as an argument, only the history of that user is displayed.
last mina
If you list multiple usernames, you can see entries that match any one of them. If the name is long, it may be truncated in the default output, so you can display the full field using util-linux's -w or --fullnames option.
last -w mina alex
Viewing records of a specific terminal
By specifying a terminal name, you can check only the sessions created from that terminal. pts/0 is commonly seen in virtual terminals such as SSH, and tty1 can represent a local virtual console.
last pts/0
According to the manual, tty0 can be abbreviated as 0, but in documents and scripts, using the full terminal name makes the intention clear.
Limiting the number of outputs
To quickly check only recent records, specify the maximum number of entries with -n.
last -n 10
You can abbreviate it like -10, but the -n 10 format is easier to read in scripts and documents and avoids confusion with other options.
Querying by period and specific time
Specifying start and end times
-s specifies the start time of the query, and -t specifies the end time. By combining the two options, you can narrow down a specific period.
last -s '2026-09-01 00:00' -t '2026-09-19 00:00'
If only the date is specified, it is generally interpreted as 00:00:00 of that date. To query the entire day, it is clear to set the end boundary as 00:00 of the following day.
Using Relative Time Expressions
The util-linux last command supports relative time expressions such as today, yesterday, now, and -7days.
last -s yesterday last -s -7days
If you need to repeatedly compare automated results, it is better for reproducibility to use explicit dates and time zones rather than relative expressions, which vary depending on the execution time.
Finding Users Logged In at a Specific Time
-p shows users who were logged in at the specified time. This can be useful when checking sessions that were active at the time of an incident.
last -p '2026-09-18 21:30'
The results are calculated based on the login/logout records remaining in wtmp, so it cannot restore missing or corrupted records.
Clearly Displaying Time Format
Viewing All Login/Logout Times
The basic output may omit the year or part of the time to reduce screen width. -F displays the full date and time for logins and logouts.
last -F -n 10
Viewing in ISO format with time zone
When comparing logs from other servers or delivering results externally, --time-format iso is useful. The ISO format includes time zone information, which can reduce confusion in interpreting times.
last --time-format iso -n 10
When comparing the sequence of events across multiple systems, you should also check whether each server's system time and time zone settings are correct.
Checking reboot and system shutdown records
Viewing reboot history
reboot is a pseudo user recorded when the system boots, not an actual user account. The following command shows the reboot history currently retained in the wtmp file.
last reboot
The display range is up to the currently preserved wtmp data. If older reboots are not visible, it might not be that there were no records, but that they have been rotated.
Displaying Shutdowns and Runlevel Changes
-x displays system shutdown and runlevel change records along with normal login records. It is helpful when checking whether a normal shutdown was recorded just before a reboot.
last -x -n 30
You can also narrow down to only shutdown entries using last shutdown. However, in situations where the shutdown record could not be left, such as an abnormal power-off, there may be no normal shutdown entries.
Interpreting the Status Displayed in the Output
| Display | Common Meaning | Things to Check |
|---|---|---|
still logged in |
No logout records yet | Reconfirm whether it is the current session with who or w |
still running |
The boot session has not ended | Check whether it is the current boot with uptime |
crash |
Interpreted as the boot session ended without a normal logout | Investigate along with kernel, journal, and hardware logs |
gone - no logout |
Could not find a corresponding logout record | Check for possibilities of log loss, reboot, or session record issues |
wtmp begins |
Start of the oldest record in the current input file | Check for the presence of rotated previous files |
Each mark is a clue for investigation, not definitive evidence of the cause. For example, seeing crash does not only indicate a hardware failure; you should also check the kernel logs, systemd journal, and virtualization platform events.
Previous wtmp files and log rotation
Reading other record files
-f reads a specified wtmp formatted file instead of the default file. Depending on the distribution's log rotation settings, previous records may remain in /var/log/wtmp.1 and so on.
last -f /var/log/wtmp.1
In util-linux, you can specify -f multiple times to process several files. Check the actual filenames and permissions in your system settings first.
Caution when handling compressed records
If rotated files are compressed with gzip or similar, do not assume that last can read them by automatically decompressing. Copy and decompress them in a restricted workspace without damaging the originals, and then read with -f. For investigation purposes, also record the hash and preservation procedure of the original.
Checking Failed Login Attempts
The Relationship Between lastb and btmp
lastb is similar to last, but by default it reads /var/log/btmp to display failed login attempts. Depending on the distribution, administrator privileges may be required.
sudo lastb -n 20
It helps to look at remote addresses and usernames with repeated failures, but on servers exposed to the internet, automated scanning is common, so do not conclude a breach based on individual attempts.
Comparing with Successful Records
It is meaningful to compare successful logins, SSH authentication logs, firewall, and access control records during the same time period.
last --time-format iso -s '2026-09-18 00:00' sudo lastb --time-format iso -s '2026-09-18 00:00'
The location and method of accessing authentication logs vary depending on the distribution and logging configuration. On systems using the systemd journal, also check the journal of the related service units.
Order of Use for Security Checks
First, fix the search scope and time frame
Record the start and end times of the incident to be investigated and the server's time zone. If possible, use --time-format iso to include time zone information in the output, and also check the time synchronization status of multiple servers.
Cross-check users, hosts, and terminals
Look for unexpected users, remote addresses different from usual, and abnormal login times and session lengths. Since the owner or location of an IP address can change and is affected by proxies, VPNs, and NAT, do not identify the user based on a single address alone.
Check for reboots and log gaps
Check last reboot, last -x, and wtmp begins to determine the range of the records and boot boundaries. Compare with log rotation times to see if there are any unexplained gaps.
Make judgments with other evidence
Cross-verify the last results with SSH authentication logs, the systemd journal, command audit logs, and firewall, VPN, and cloud access records. If an incident is suspected, do not alter the original logs and preserve them according to the organization’s response procedures.
Limitations of last records
- Dependence on local files: If
wtmpis missing or the service does not log, the results may be empty. - Retention period limitation: Records after log rotation and deletion cannot be retrieved from the current file.
- Possibility of tampering: An attacker with sufficient privileges can modify or delete local records.
- Time dependence: Changing the system clock or incorrect time zone setting can confuse the order of events and session times.
- Environmental differences: Containers, minimal installation environments, and some remote access methods may not leave the expected
wtmpentries.
Therefore, last is useful for quickly gauging the situation and starting investigation, but it does not replace complete audit logs or centralized security records.
Comparison with commands similar to last
| Command | Main Purpose | Suitable situations |
|---|---|---|
last |
Past login/logout history | Check session and boot records remaining in wtmp |
lastb |
Failed login history | Check authentication failures recorded in btmp |
who |
Current logged-in users | Check users and terminals of current sessions |
w |
Current users and their running activities | Check login users, idle times, and processes |
lastlog or lslogins |
Last login by account | Check accounts that have not been used for a long time or the last login |
Frequently Asked Questions
Why does last return no results?
It could be that /var/log/wtmp does not exist, is empty, or the system is configured not to record logins in that file. Check the file's existence, permissions, and logging policies. An empty result does not mean there were no login records at all.
Does 'still logged in' mean currently logged in?
It means there is no logout record corresponding to that login. To check the actual current session, it is better to use who, w, loginctl, etc. Older sessions may appear that way due to abnormal termination or missing records.
How can I check old login records?
If there are files like the rotated log wtmp.1, you can read them with last -f filename. For compressed files, use a decrypted copy and do not modify the original directly.
Can hacking be determined from just the last command results?
No. Unexpected logins are important clues, but local wtmp records can be incomplete or tampered with. You need to analyze them together with authentication logs, network records, command audit logs, and system changes.
Summary
Recent login history can be checked with last, specific users with last username, reboot records with last reboot, and failed logins with lastb. For periods, use -s and -t, for a specific point in time -p, and for clear time display --time-format iso can be used.
The results of last are valid only within the range of the currently available wtmp records. In a security investigation, you should first check the timezone and log retention range and cross-verify with other records. Related basic tools can be viewed together in the List of commonly used commands in Linux.









