Linux who Command: List Logged-In Users
who shows the currently logged-in users, their terminals, and login times based on login records. It is useful for quickly checking active login sessions on servers where multiple users are connected.
What is the who command?
The basic output is mainly composed of the username, terminal device, and login time. If it is a remote connection, the host information may be displayed at the end. It is not a command that shows all running processes or the privileges of the current user.
Basic syntax
who [option]
The installed implementation and options may vary depending on the distribution. Check the current system's description with man who.
Examples
Viewing active login sessions
If the same user is logged in on multiple terminals, multiple lines may appear.
who
Display column headings
First, check the meaning of each output column.
who -H
Login User Summary
Displays the usernames and total session counts captured in the current login records.
who -q
Read one line of login session
who shows the sessions registered in the current login records. In the example, the user name, terminal, login time, and remote access location appear in order.
who
Example output (time and terminal display may vary depending on the environment):
alice pts/0 2026-09-28 09:00 (192.0.2.10)
If the same user is connected to multiple terminals, multiple lines may appear. Conversely, in containers or some non-interactive sessions, there may be no login records even if actual processes exist, resulting in empty output. To see the process activity of the current logged-in user, use w.
Main Options and Format
| Options/Format | Description |
|---|---|
-H |
Displays the headers of the output columns. |
-q |
Briefly displays login usernames and their total count. |
-u |
Displays additional information such as idle time. |
-b |
Displays the system's last boot time. |
Precautions when using
who usually reads login records from the utmp series. In containers, minimal installation environments, or sessions that do not leave records, the output may be empty or partially visible even if the actual processes exist. To fully audit connection traces, service logs and authentication logs should also be checked.
Frequently Asked Questions
If who outputs nothing, does that mean there are no users?
Not necessarily. The current environment may not provide login records, so check both the terminal session and the system logs together.
Official Documentation
The exact behavior of the option and implementation differences can be found in the official documentation related to who.









