Home / Alt manpages / users(1)

  • users(1)
  • User command
  • linux

See Who Is Logged In with users(1)

You will use users to print the login names recorded for the current host, check which file it read, and avoid confusing a historical login database with a list of active sessions. The command prints names only, so it is useful for a quick human check or a small shell pipeline, not as a complete session audit.

These examples use GNU coreutils 9.4, from the installed package version 9.4-3ubuntu6.3. Allow five minutes. You need a shell and a Linux system with the users command installed. The normal checks are read-only and do not need sudo.

1. Check the installed command

Confirm that the shell will run the expected binary and record its version:

$ command -v users
/usr/bin/users
$ users --version | head -n 1
users (GNU coreutils) 9.4

The exact path can differ on another installation. The version matters when you are comparing output between machines, because this guide describes the GNU implementation shipped here, not every program with a similar name.

Checkpoint

If command -v users prints nothing, stop here. Install the package through your normal system-management process rather than copying a binary from another host.

2. Print the current login names

Run the command without an argument:

$ users
andy andy andy andy

Your output will contain different names and may contain the same name more than once. Each printed name represents a record read from the current login database. The command does not produce one name per unique account, and it does not show terminals, login times, remote addresses or idle time.

On this system, the default input is /var/run/utmp. The file is normally maintained by login services, terminals and session managers. A zero-length result can be legitimate when there are no current records. It can also point to a service or accounting problem, so do not treat an empty line as proof that nobody is connected.

Capture the exit status when a script needs to distinguish a successful command from a failed read:

$ users > /tmp/current-users.txt
$ status=$?
$ printf 'users exit status: %s\n' "$status"
users exit status: 0
$ sed -n '1p' /tmp/current-users.txt

This example writes a temporary report under /tmp. It does not alter login accounting. Remove that report when it is no longer needed, especially on a shared machine, because account names can be sensitive operational information:

$ rm -- /tmp/current-users.txt

The removal is irreversible. If you need the report for an incident record, move it to the approved evidence location instead of leaving it in a world-readable temporary directory.

3. Inspect an explicit accounting file

The optional argument is a file. Pass it after the command to make the input explicit:

$ users /var/run/utmp
andy andy andy andy

This should normally match an argument-free invocation. It is a useful check when reviewing a script or diagnosing a different environment. Use an absolute path so that a changed working directory cannot make the command read an unintended file.

GNU users also documents /var/log/wtmp as a common alternative:

$ users /var/log/wtmp | cut -d ' ' -f 1-12
andy andy andy andy andy andy andy andy andy andy andy andy

Do not read this output as the current session list. wtmp records login accounting over time, so it can contain names from earlier sessions and can be much larger than utmp. The command prints names from the file in its record order, without adding timestamps or marking logouts.

Safety boundary

Reading these files is not the same as editing them. Do not truncate, remove or manually rewrite /var/run/utmp or /var/log/wtmp to hide a session or repair output. That can damage accounting and complicate incident investigation. If the files are corrupt or permissions are wrong, preserve them and investigate the service that owns login accounting.

4. Use the built-in help when the syntax is uncertain

GNU users has a deliberately small interface:

$ users --help
Usage: users [OPTION]... [FILE]
Output who is currently logged in according to FILE.
If FILE is not specified, use /var/run/utmp.  /var/log/wtmp as FILE is common.

      --help        display this help and exit
      --version     output version information and exit

There is no option here for JSON, sorting, deduplication, usernames from a particular terminal or filtering by time. Add those operations as separate, visible pipeline steps only when you have decided what the input means. For example, sort -u produces a unique name list, but it discards the repeated-record information that may matter when you are checking session accounting:

$ users /var/run/utmp | tr ' ' '\n' | sort -u
andy

That pipeline is ordinary, unprivileged processing of command output. Its result answers "which names appear at least once?", not "how many sessions exist?" and not "which accounts are authenticated right now?".

5. Choose a fuller tool when names are not enough

Use users for a compact name-only view. If you need terminals, login times, remote hosts or process details, use a tool designed to display those fields, such as who or w. The users(1) manual also points to getent(1) and who(1) as related commands.

Do not infer identity from a process list alone. A service account can own processes without having an interactive login, and a login record can outlive the event you are investigating if accounting is delayed or damaged. Correlate the output with the question you are answering and keep the source file and command version in your notes.

Done means

  • users --version identified the GNU coreutils implementation you tested.
  • You ran users and understand that repeated names are possible.
  • You know the default input is /var/run/utmp.
  • You can pass an explicit file without mistaking /var/log/wtmp for a live-session list.
  • You have not modified either accounting file or granted yourself unnecessary elevated access.
  • You will use who, w or another fuller tool when names alone cannot answer the question.