Check for Missing lastlog Entries with chklastlog
You will run chklastlog to compare login records in /var/log/wtmp with per-user records in /var/log/lastlog. A reported account is a lead for investigation: it is not, by itself, proof that the account was compromised. Allow about ten minutes for a single host. You need a shell and the chkrootkit package. The examples below only read files, so they normally need no elevated privileges.
The route
Jump straight to the step you need, or tick off Done means at the end.
1. Check the installed version and command
On the system used for this guide, Debian package version chkrootkit 0.58b-1 provides the command. Check your own package before comparing results with another host, because this is an old utility with platform-specific limitations:
$ dpkg-query -W -f='${Package} ${Version}\n' chkrootkit
chkrootkit 0.58b-1
$ command -v chklastlog
/usr/sbin/chklastlog
If you use a non-Debian distribution, use its package query tool and confirm that the command is actually installed. Do not copy the version shown above into an incident record unless it is the version your command reports.
2. Confirm the two input files are readable
chklastlog reads the whole wtmp login and logout database, then checks each user it finds against lastlog. Check both paths before running it:
$ ls -l /var/log/wtmp /var/log/lastlog
$ test -r /var/log/wtmp && echo 'wtmp: readable'
wtmp: readable
$ test -r /var/log/lastlog && echo 'lastlog: readable'
lastlog: readable
The command needs read access to both files. If either test fails, stop and arrange access through your normal operations process. Do not change ownership or permissions just to make a rootkit check run. That would change the evidence and could expose authentication history.
Checkpoint: both files exist and are readable, and you have noted their paths. The manual calls the second database lastlog in its file list, although its description also uses the spelling lastlogin; on this Linux installation the path is /var/log/lastlog.
3. Run the comparison
Run the command without options. It has no documented flags or interactive mode:
$ chklastlog
$ status=$?
$ printf 'chklastlog exit status: %s\n' "$status"
chklastlog exit status: 0
A clean run normally prints no account names and returns status 0, as on the machine used here. Capture the status immediately. Running another command first would replace the status you are trying to record.
The useful output, when present, is a list of users found in wtmp without corresponding information in lastlog. Save the terminal output with the host name, time and package version. Do not edit either log to make the result disappear.
4. Treat a reported user as an investigation lead
A missing lastlog entry can suggest that someone tried to cover their tracks, which is why the tool exists. It does not establish who changed the file, when it happened or whether the user account was compromised. First preserve the original records and record the exact command output. Then review the account, authentication logs and other independent evidence under your organisation's incident procedure.
For a quick, read-only record of the account database, you can list the named account without changing it:
$ getent passwd -- 'ACCOUNT_NAME'
ACCOUNT_NAME:x:1001:1001:Account Name:/home/ACCOUNT_NAME:/bin/bash
Replace ACCOUNT_NAME with the name printed by chklastlog. If the lookup returns nothing, that is another useful fact to record, not a reason to create or delete an account. Avoid locking, resetting or removing the account until an authorised responder has decided that containment is required; those actions can destroy useful evidence or interrupt a legitimate service.
5. Understand what the check cannot prove
The result is bounded by the two databases. The manual warns that wtmp may itself be incomplete because not every program records activity through utmp logging. A clean result therefore does not prove that all logins were legitimate or that the host is free of rootkits.
There is also a timing blind spot: if a user logs in after a lastlog entry was deleted, the later login can recreate that entry and the deletion may no longer be detected. Run the check promptly when investigating a suspected event, and compare it with logs that have separate storage or collection paths.
Finally, the program was originally designed for SunOS 4.x. The installed package is usable for this Linux workflow, but the manual explicitly says that output is undefined on other systems. Do not use an unverified result as a cross-platform compliance control.
6. Record and repeat safely
This utility makes no documented changes to the log files, so there is no undo operation. Save the command output and status in your case notes, then repeat only when you need a fresh comparison:
$ hostname
HOSTNAME
$ date --iso-8601=seconds
2026-09-22T16:00:00+01:00
$ chklastlog
$ printf 'exit=%s\n' "$?"
exit=0
Replace the illustrative host name and time with the actual output from your machine. If the command cannot open a file, retain that error, check the path and permissions again, and investigate log rotation or an unusual logging layout. Do not assume that an empty result means the files were successfully checked unless the command completed and you captured its status.
Done means
- The installed
chkrootkitversion and command path are recorded. /var/log/wtmpand/var/log/lastlogwere readable without changing their permissions.- The complete
chklastlogoutput and immediate exit status are saved. - Any reported account is being treated as an investigation lead, not as automatic proof of compromise.
- You have accounted for incomplete
wtmplogging, later logins recreating entries and the tool's platform limitation.