6 October 2026 · One command a day
How do I see the last logins to my Linux server?
The last command lists recent logins to your server, newest first. It shows who logged in, where they connected from and how long they stayed. Use it to check that only the people you expect are getting into your VPS, or to find out when someone was last on it.
The command
last -n 20
last reads the login record that the system keeps in /var/log/wtmp and prints each session on one line. -n 20 limits the output to the 20 most recent entries, so you do not have to scroll through weeks of history. On Ubuntu 24.04 any user can read this file, so you do not need sudo. To see only one account, put its name at the end, for example last -n 20 user.
What you will see
user pts/0 127.0.0.1 Tue Oct 6 09:12 still logged in
user pts/1 office.example.c Mon Oct 5 21:40 - 22:14 (00:34)
reboot system boot 6.8.0-45-generic Mon Oct 5 03:02 still running
user pts/0 127.0.0.1 Sun Oct 4 18:05 - crash (08:57)
root pts/0 office.example.c Sat Oct 3 10:20 - 10:31 (00:11)
wtmp begins Thu Oct 1 00:00:02 2026
The columns are, in order: the username, the terminal, where the connection came from, the start time, and the end time followed by the length of the session in hours and minutes. A pts/ terminal usually means a remote SSH session. still logged in means the session is open now. Each reboot line marks a boot and shows which kernel the server started with. crash means the session never closed cleanly because the server went down. The host column is cut off at 16 characters. The last line tells you how far back the record goes.
When to use it
- After a burst of failed SSH attempts, to check that no unknown address actually got in. Use it together with checking which IPs fail2ban has banned.
- When a file or setting changed and you want to know who was logged in at the time.
- After an unexpected restart, to see when the reboot happened and which sessions it cut off.
Watch out for
last only covers the period since /var/log/wtmp was last rotated. Ubuntu rotates the file with logrotate and keeps one older copy, so if the wtmp begins date is more recent than the login you are looking for, check the older file with last -n 20 -f /var/log/wtmp.1. Also bear in mind that anyone with root access can edit these files. An empty or tidy history is not proof that nobody got in.
Questions people ask
How do I see failed login attempts instead?
Run sudo lastb -n 20. It reads /var/log/btmp, which records failed logins and needs root to read.
How do I see the full hostname or IP address?
Add -a to move the host to the last column, where it is not cut off. Add -i to show IP addresses instead of hostnames.
You can only read a server's own login history on a server you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.
Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.
Affiliate link.