Read Linux Login Sessions and Load with w

The w command shows who is logged in, where each session came from, what its processes are doing, and how busy the machine has been, all read-only.

It reads the host's login and process information; it does not disconnect anyone or alter a service. Allow about five minutes. These examples use procps 4.0.4, installed here as package version 2:4.0.4-4ubuntu3.3.

Your rows and times will be different because they describe the current machine.

1. Confirm the installed command

Check which binary is being run and read its version. Both commands are ordinary, unprivileged checks:

$ command -v w
/usr/bin/w
$ w --version
w from procps-ng 4.0.4
$ dpkg-query -W -f='${Package} ${Version}\n' procps
procps 2:4.0.4-4ubuntu3.3

The command accepts an optional user name. It also has short and long option forms, so scripts can use the longer spelling when clarity matters:

$ w --help
Usage:
 w [options] [user]

Checkpoint: if command -v w points somewhere unexpected, stop and inspect your PATH before trusting the output. The package version tells you which local behaviour to compare with the manual.

2. Read the normal report

Run w with no arguments:

$ w
 19:16:35 up 16 days,  3:17,  3 users,  load average: 4.64, 3.38, 2.47
USER     TTY      FROM               LOGIN@   IDLE   JCPU   PCPU  WHAT
alice             203.0.113.45      19:15    6:49m  0.00s   ?    sshd: alice [priv]

The first line gives the current time, uptime, number of logged-in users, and one-, five- and fifteen-minute load averages. The table then shows each login name, terminal, remote host, login time, idle time, JCPU, PCPU and current command. A blank terminal or a ? is real information, not a promise every field will be populated on every session.

3. Narrow the view to one user

Put a login name after the options to show only that user's information:

$ w alice
 19:16:35 up 16 days,  3:17,  3 users,  load average: 4.64, 3.38, 2.47
USER     TTY      FROM               LOGIN@   IDLE   JCPU   PCPU  WHAT
alice             203.0.113.45      19:15    6:49m  0.00s   ?    sshd: alice [priv]

Replace alice with an exact account name from your system. If there is no matching logged-in session, the header may still be printed with no data rows. That is a useful result: the user is not represented in the current login database, rather than evidence the command failed.

Checkpoint: use this form when you need to inspect your own sessions without mentally filtering a busy host. Do not infer a user is absent from the system altogether; w reports current logins, not all local accounts.

4. Choose a compact format

Use short output when login time, JCPU and PCPU would distract from the current command:

$ w --short
 19:16:35 up 16 days,  3:17,  3 users,  load average: 4.64, 3.38, 2.47
USER     TTY      FROM               IDLE   WHAT
alice             203.0.113.45      6:49m  sshd: alice [priv]

Use --no-header when another program will consume just the rows:

$ w --no-header --short
alice             203.0.113.45      6:49m  sshd: alice [priv]

Do not parse these columns by fixed character positions without testing the exact procps version and expected session types. Host names, user names and command lines vary in width.

5. Make remote sessions easier to identify

The local build defaults to showing the remote host in the FROM column. --from toggles that field, and --ip-addr asks for an IP address instead of a host name when possible:

$ w --ip-addr --short
 19:16:35 up 16 days,  3:17,  3 users,  load average: 4.64, 3.38, 2.47
USER     TTY      FROM               IDLE   WHAT
alice             203.0.113.45      6:49m  sshd: alice [priv]

The manual allows a distribution maintainer or administrator to compile a different default for FROM. If that column appears or disappears unexpectedly, use --from explicitly and check the installed version.

6. Add process IDs when the row needs follow-up

Use --pids to include the PID of the login process or the process shown in WHAT:

$ w --pids --short
 19:16:35 up 16 days,  3:17,  3 users,  load average: 4.64, 3.38,  2.47
USER     TTY      FROM               IDLE   WHAT
alice             203.0.113.45      6:49m  2533405/2533405 sshd: alice [priv]

The exact PID and formatting are transient. If you need to investigate that process, use the PID immediately with a separate read-only tool such as ps. A PID can be reused after a process exits, so do not treat an old report as a permanent identity.

7. Handle confusing output safely

w reads /var/run/utmp for logged-in users and /proc for process information. A damaged, stale or unusually configured login record can therefore produce blank fields or surprising rows. First repeat the command and compare it with who and ps; do not edit utmp or kill a process merely because one display looks odd.

The --no-current option changes how the current process and CPU times are worked out by ignoring the username. The manual describes it as useful for comparing output after su with and without the option. It is a diagnostic switch, not a way to hide a login:

$ w --no-current
 19:16:35 up 16 days,  3:17,  3 users,  load average: 4.64, 3.38, 2.47
USER     TTY      FROM               LOGIN@   IDLE   JCPU   PCPU  WHAT
alice             203.0.113.45      19:15    6:49m  0.00s   ?    sshd: alice [priv]

No example here needs sudo. Elevated privileges may change what other tools can inspect, but they do not make w's login records more truthful and are not a repair for missing data.

Done means