The w command shows who is logged in, where each session came from, what its processes are doing, and how busy the machine has been, all read-only.
It reads the host's login and process information; it does not disconnect anyone or alter a service. Allow about five minutes. These examples use procps 4.0.4, installed here as package version 2:4.0.4-4ubuntu3.3.
Your rows and times will be different because they describe the current machine.
Check which binary is being run and read its version. Both commands are ordinary, unprivileged checks:
$ command -v w
/usr/bin/w
$ w --version
w from procps-ng 4.0.4
$ dpkg-query -W -f='${Package} ${Version}\n' procps
procps 2:4.0.4-4ubuntu3.3
The command accepts an optional user name. It also has short and long option forms, so scripts can use the longer spelling when clarity matters:
$ w --help
Usage:
w [options] [user]
Checkpoint: if command -v w points somewhere unexpected, stop and inspect your PATH before trusting the output. The package version tells you which local behaviour to compare with the manual.
Run w with no arguments:
$ w
19:16:35 up 16 days, 3:17, 3 users, load average: 4.64, 3.38, 2.47
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
alice 203.0.113.45 19:15 6:49m 0.00s ? sshd: alice [priv]
The first line gives the current time, uptime, number of logged-in users, and one-, five- and fifteen-minute load averages. The table then shows each login name, terminal, remote host, login time, idle time, JCPU, PCPU and current command. A blank terminal or a ? is real information, not a promise every field will be populated on every session.
WHAT. Both are CPU times, not elapsed wall-clock durations.Put a login name after the options to show only that user's information:
$ w alice
19:16:35 up 16 days, 3:17, 3 users, load average: 4.64, 3.38, 2.47
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
alice 203.0.113.45 19:15 6:49m 0.00s ? sshd: alice [priv]
Replace alice with an exact account name from your system. If there is no matching logged-in session, the header may still be printed with no data rows. That is a useful result: the user is not represented in the current login database, rather than evidence the command failed.
Checkpoint: use this form when you need to inspect your own sessions without mentally filtering a busy host. Do not infer a user is absent from the system altogether; w reports current logins, not all local accounts.
Use short output when login time, JCPU and PCPU would distract from the current command:
$ w --short
19:16:35 up 16 days, 3:17, 3 users, load average: 4.64, 3.38, 2.47
USER TTY FROM IDLE WHAT
alice 203.0.113.45 6:49m sshd: alice [priv]
Use --no-header when another program will consume just the rows:
$ w --no-header --short
alice 203.0.113.45 6:49m sshd: alice [priv]
Do not parse these columns by fixed character positions without testing the exact procps version and expected session types. Host names, user names and command lines vary in width.
The local build defaults to showing the remote host in the FROM column. --from toggles that field, and --ip-addr asks for an IP address instead of a host name when possible:
$ w --ip-addr --short
19:16:35 up 16 days, 3:17, 3 users, load average: 4.64, 3.38, 2.47
USER TTY FROM IDLE WHAT
alice 203.0.113.45 6:49m sshd: alice [priv]
The manual allows a distribution maintainer or administrator to compile a different default for FROM. If that column appears or disappears unexpectedly, use --from explicitly and check the installed version.
Use --pids to include the PID of the login process or the process shown in WHAT:
$ w --pids --short
19:16:35 up 16 days, 3:17, 3 users, load average: 4.64, 3.38, 2.47
USER TTY FROM IDLE WHAT
alice 203.0.113.45 6:49m 2533405/2533405 sshd: alice [priv]
The exact PID and formatting are transient. If you need to investigate that process, use the PID immediately with a separate read-only tool such as ps. A PID can be reused after a process exits, so do not treat an old report as a permanent identity.
w reads /var/run/utmp for logged-in users and /proc for process information. A damaged, stale or unusually configured login record can therefore produce blank fields or surprising rows. First repeat the command and compare it with who and ps; do not edit utmp or kill a process merely because one display looks odd.
The --no-current option changes how the current process and CPU times are worked out by ignoring the username. The manual describes it as useful for comparing output after su with and without the option. It is a diagnostic switch, not a way to hide a login:
$ w --no-current
19:16:35 up 16 days, 3:17, 3 users, load average: 4.64, 3.38, 2.47
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
alice 203.0.113.45 19:15 6:49m 0.00s ? sshd: alice [priv]
No example here needs sudo. Elevated privileges may change what other tools can inspect, but they do not make w's login records more truthful and are not a repair for missing data.
w is procps-ng 4.0.4 on this machine.WHAT process.