Linux who Command: List Logged-In Users

who shows the currently logged-in users, their terminals, and login times based on login records. It is useful for quickly checking active login sessions on servers where multiple users are connected.

What is the who command?

The basic output is mainly composed of the username, terminal device, and login time. If it is a remote connection, the host information may be displayed at the end. It is not a command that shows all running processes or the privileges of the current user.

Basic syntax

who [option]

The installed implementation and options may vary depending on the distribution. Check the current system's description with man who.

Examples

Viewing active login sessions

If the same user is logged in on multiple terminals, multiple lines may appear.

who

Display column headings

First, check the meaning of each output column.

who -H

Login User Summary

Displays the usernames and total session counts captured in the current login records.

who -q

Read one line of login session

who shows the sessions registered in the current login records. In the example, the user name, terminal, login time, and remote access location appear in order.

who

Example output (time and terminal display may vary depending on the environment):

alice pts/0 2026-09-28 09:00 (192.0.2.10)

If the same user is connected to multiple terminals, multiple lines may appear. Conversely, in containers or some non-interactive sessions, there may be no login records even if actual processes exist, resulting in empty output. To see the process activity of the current logged-in user, use w.

Main Options and Format

Options/Format Description
-H Displays the headers of the output columns.
-q Briefly displays login usernames and their total count.
-u Displays additional information such as idle time.
-b Displays the system's last boot time.

Precautions when using

who usually reads login records from the utmp series. In containers, minimal installation environments, or sessions that do not leave records, the output may be empty or partially visible even if the actual processes exist. To fully audit connection traces, service logs and authentication logs should also be checked.

Frequently Asked Questions

If who outputs nothing, does that mean there are no users?

Not necessarily. The current environment may not provide login records, so check both the terminal session and the system logs together.

Official Documentation

The exact behavior of the option and implementation differences can be found in the official documentation related to who.

More in This Category
Linux Tutorial / Compare Files with diff and cmp

Linux Tutorial / Compare Files with diff and cmp

Use diff and cmp to compare two files, read unified diff output, and distinguish a detected difference from an actual command error.

Linux nc Command: Test TCP and UDP Connections

Linux nc Command: Test TCP and UDP Connections

Learn how to test TCP and UDP Connections with the Linux nc command, including practical examples, key options, and important precautions.

Linux uptime Command: Check Uptime and Load Averages

Linux uptime Command: Check Uptime and Load Averages

Learn how to use the Linux uptime command to check how long the system has been running and interpret load averages, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux dig Command: Query DNS Records in Detail

Linux dig Command: Query DNS Records in Detail

Learn how to query DNS Records in Detail with the Linux dig command, including practical examples, key options, and important precautions.

Linux getent Command: Query Users, Groups, and Other NSS Databases

Linux getent Command: Query Users, Groups, and Other NSS Databases

Learn how to query Users, Groups, and Other NSS Databases with the Linux getent command, including practical examples, key options, and important precautions.

Bash Command Operators Explained: ;, &&, ||, &, and |

Bash Command Operators Explained: ;, &&, ||, &, and |

Understand how Bash operators run commands sequentially, conditionally, in the background, or through pipelines, with practical examples and precedence guidance.

Linux fdisk Command: Inspect and Edit Disk Partitions

Linux fdisk Command: Inspect and Edit Disk Partitions

Learn how to inspect and Edit Disk Partitions with the Linux fdisk command, including practical examples, key options, and important precautions.

Linux ls Command: List Files and Directories

Linux ls Command: List Files and Directories

Learn how to use the Linux ls command to list files and directories with permissions, sizes, timestamps, and sorting options, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux whoami Command: Show the Effective User Name

Linux whoami Command: Show the Effective User Name

Learn how to show the Effective User Name with the Linux whoami command, including practical examples, key options, and important precautions.

Linux dnf Command: Manage RPM Distribution Packages

Linux dnf Command: Manage RPM Distribution Packages

Learn how to manage RPM Distribution Packages with the Linux dnf command, including practical examples, key options, and important precautions.