Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

6 October 2026 · One command a day

How do I see the last logins to my Linux server?

The last command lists recent logins to your server, newest first. It shows who logged in, where they connected from and how long they stayed. Use it to check that only the people you expect are getting into your VPS, or to find out when someone was last on it.

The command

last -n 20

last reads the login record that the system keeps in /var/log/wtmp and prints each session on one line. -n 20 limits the output to the 20 most recent entries, so you do not have to scroll through weeks of history. On Ubuntu 24.04 any user can read this file, so you do not need sudo. To see only one account, put its name at the end, for example last -n 20 user.

What you will see

user     pts/0        127.0.0.1        Tue Oct  6 09:12   still logged in
user     pts/1        office.example.c Mon Oct  5 21:40 - 22:14  (00:34)
reboot   system boot  6.8.0-45-generic Mon Oct  5 03:02   still running
user     pts/0        127.0.0.1        Sun Oct  4 18:05 - crash  (08:57)
root     pts/0        office.example.c Sat Oct  3 10:20 - 10:31  (00:11)

wtmp begins Thu Oct  1 00:00:02 2026

The columns are, in order: the username, the terminal, where the connection came from, the start time, and the end time followed by the length of the session in hours and minutes. A pts/ terminal usually means a remote SSH session. still logged in means the session is open now. Each reboot line marks a boot and shows which kernel the server started with. crash means the session never closed cleanly because the server went down. The host column is cut off at 16 characters. The last line tells you how far back the record goes.

When to use it

Watch out for

last only covers the period since /var/log/wtmp was last rotated. Ubuntu rotates the file with logrotate and keeps one older copy, so if the wtmp begins date is more recent than the login you are looking for, check the older file with last -n 20 -f /var/log/wtmp.1. Also bear in mind that anyone with root access can edit these files. An empty or tidy history is not proof that nobody got in.

Questions people ask

How do I see failed login attempts instead?

Run sudo lastb -n 20. It reads /var/log/btmp, which records failed logins and needs root to read.

How do I see the full hostname or IP address?

Add -a to move the host to the last column, where it is not cut off. Add -i to show IP addresses instead of hostnames.

You can only read a server's own login history on a server you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: How do I see which IPs fail2ban has banned? · How do I list ufw firewall rules with numbers on Ubuntu? · How do I list all my SSL certificates and their expiry dates with certbot?