Read Login and Reboot History with last and lastb

When something odd happened overnight, last and lastb are usually the fastest way to see who logged in and whether anyone was trying to. They can also show when the box rebooted. The examples use the util-linux implementation installed here. The package is util-linux 2.39.3-9ubuntu6.6; the command itself reports util-linux 2.41.3, so check the local help and manpage when reproducing this on another release.

Allow about ten minutes. You need a shell and readable accounting files. These commands read login records only, they do not log users out, rotate logs, delete entries or change authentication settings. Most normal checks do not need sudo.

1. Show recent successful login records

Run last with a small limit first:

$ last --limit 5
alice    pts/5        tmux(1998).%143  Thu Sep 24 16:02   still logged in
alice    pts/5        tmux(1998).%142  Thu Sep 24 16:01 - 16:01  (00:00)
alice    pts/4        203.0.113.53     Thu Sep 24 16:01 - 16:22  (00:21)
alice    pts/3        tmux(1998).%141  Thu Sep 24 15:58   still logged in
alice    pts/0        tmux(1998).%140  Thu Sep 24 15:57   still logged in

wtmp begins Fri Jun 12 00:07:47 2026

Your usernames, terminals, hosts and times will differ. The output is read backwards from /var/log/wtmp, so the newest records appear first. An entry still marked still logged in has no logout record yet. The final wtmp begins line tells you how far back this file reaches, not how far back the operating system can remember in theory.

Checkpoint: confirm the command exits successfully and the result is from the expected file:

$ printf '%s\n' "$?"
0
$ last --file /var/log/wtmp --limit 1

2. Filter by user, terminal or reboot

Put one or more usernames or terminal names after the options. The arguments are filters, not searches across every field. Terminal names may be abbreviated, so last 0 matches tty0.

$ last --limit 10 alice
$ last --limit 10 pts/4
$ last reboot

The special pseudo-user reboot displays system boot records. For a useful incident timeline, add --system to include shutdown entries and run-level changes:

$ last --system --time-format iso --limit 10 reboot
reboot   system boot  6.8.0-139-gener* 2026-09-11T15:58:00+01:00   still running

Do not infer that a missing user proves the user never logged in. The record may have aged out, logging may not have been enabled, or the account may have used a different mechanism. Treat this as evidence from wtmp, not a complete authentication history.

3. Make timestamps suitable for investigations

The default short format is convenient at a terminal but can be ambiguous in a copied report. Use --time-format iso when timezone information matters:

$ last --time-format iso --limit 3
alice    pts/5        tmux(1998).%143  2026-09-24T16:02:49+01:00   still logged in
alice    pts/5        tmux(1998).%142  2026-09-24T16:01:22+01:00 - 2026-09-24T16:01:22+01:00  (00:00)
alice    pts/4        203.0.113.53     2026-09-24T16:01:22+01:00 - 2026-09-24T16:22:44+01:00  (00:21)

The other documented formats are short, full and notime. --fulltimes is equivalent to the full timestamp format. Need the remote address rather than a resolved name? Use --ip. --dns goes the other way, attempting to translate recorded addresses into hostnames, which can be slow or misleading if DNS has changed since. Add --hostlast to put the hostname in the final column.

4. Ask who was present during a time window

Use --since and --until to bound the state calculation. The parser accepts complete timestamps, dates, times, now, yesterday, today, tomorrow, and relative values such as +5min or -5days.

$ last --since '2026-09-24 16:00' --until '2026-09-24 16:30' --time-format iso
$ last --present '2026-09-24 16:10' --time-format iso

Quote values containing spaces so the shell passes each time as one argument. --present is a shortcut for asking who was present at one specified time. Empty result? Check the time zone, the file coverage and whether the account was recorded in wtmp at all.

For scripts or reports that need stable delimiters, this installed command also advertises --tab-separated in its help output. Verify the option on the target host before depending on it, the local manpage for util-linux 2.39.3 does not describe that newer option.

5. Check failed login attempts with lastb

lastb uses the same style of filtering and formatting, but defaults to /var/log/btmp, the database of recorded bad login attempts:

$ sudo lastb --limit 20 --time-format iso

Elevated privileges may be required because btmp is normally restricted. Use sudo only when a read fails with a permission error. A successful command may print no records if there have been no recorded failures, or if the file is absent, that is not proof that every failed authentication attempt was impossible.

Warning: do not paste btmp output into a public ticket without reviewing it. Usernames, source addresses and timing can be security-sensitive. Preserve the original output and its collection time if you are handling an incident, and follow your organisation's evidence-handling rules.

6. Handle missing files without creating them blindly

The manpage says wtmp and btmp might not exist, that is a local logging configuration issue. Check the files and permissions first:

$ ls -l /var/log/wtmp /var/log/btmp
$ test -r /var/log/wtmp && echo 'wtmp is readable'
$ test -r /var/log/btmp && echo 'btmp is readable'

Do not use touch merely to make an empty result look successful, creating a log file changes system state and does not reconstruct historical records. If your logging policy requires these files, follow the distribution's documented configuration and ownership requirements, then confirm the relevant login services actually write them. That configuration work needs elevated privileges and should be planned separately.

To inspect an archived or copied accounting file, use --file rather than replacing the live log:

$ last --file /path/to/wtmp-copy --time-format iso --limit 20

This is read-only from last's point of view. Keep the copy unchanged so another investigator can reproduce the same result.

7. Stop a long scan safely

A large accounting file can take time to scan. Press Ctrl-C to send SIGINT, the program reports how far it searched and then exits. Use --limit, a user or terminal filter, a time range, or a specific file for the next attempt instead of repeatedly interrupting an unconstrained scan.

For a final sanity check, compare the command version with the target system's package record:

$ last --version
last from util-linux 2.41.3
$ last --help | sed -n '1,35p'

Option details can vary between util-linux releases. The local manpage used for this guide is generated from util-linux 2.39.3, while the executable here reports 2.41.3, so the help output is the authoritative check for options actually accepted by the installed binary.

Done means