A security-focused guide to the last command — covering login history forensics, impossible travel detection, session duration anomalies, and wtmp file integrity for incident response.

What is the last command?

The last command reads from the /var/log/wtmp binary log file and displays a list of all user login and logout events, including the source IP address for remote SSH sessions, session duration, and the terminal used. It is one of the first commands executed during any SSH-related security investigation because it provides a complete chronological record of who accessed the server, from where, and for how long — without requiring any additional tooling. The last command is available on every Linux distribution and requires no elevated privileges for viewing the current user’s own sessions, though root sees all users’ login history. On busy servers, last -n 50 limits output to the 50 most recent entries for faster initial review.

Syntax

last
last username
last -n 20
last -a
last -F
last -i
last -f /var/log/wtmp.1

last with no arguments lists all entries from wtmp, most recent first. -n N limits output to the last N entries. -a places the hostname at the end of the line (useful for wide output). -F shows full timestamps including seconds. -i displays IP addresses instead of hostnames. -f reads from an alternative wtmp file — useful for reading rotated archives.

Key Options and Flags

Flag / ParameterDescriptionSecurity Note
usernameFilter to show only login events for the specified userFilter by a specific compromised account to build a precise access timeline
-aDisplay hostname/IP at the end of each line—
-FShow full date and time including year and secondsRequired for precise incident timeline reconstruction — default output truncates timestamps
-iShow IP addresses instead of resolving hostnamesPreferred for security analysis — avoid relying on DNS resolution which can be spoofed or slow
-n NLimit output to the most recent N entries—
-f fileRead from an alternative wtmp file (e.g., rotated archives)Use to extend the investigation window beyond the current wtmp if it has been rotated
rebootFilter to show only system reboot and shutdown eventsUnexpected reboots are a security indicator — check last reboot against your maintenance schedule

Common Use Cases

Detect Impossible Travel in SSH Login History

Impossible travel is when a user account shows successful logins from two geographically distant locations within a timeframe that makes physical travel impossible. With last -iF, you can see the source IP and precise timestamp of each login. Consecutive logins from different continents within minutes are a definitive indicator of credential compromise — either the account was used from two devices simultaneously, or the legitimate user’s credentials were stolen.

last -iF username | head -20

Review All Recent Logins to Identify Unknown Source IPs

After any suspected breach, the first priority is determining if any unauthorized sessions occurred. Review all successful logins and compare source IPs against your expected list of admin IP addresses. Any unknown IP that achieved a successful login is a confirmed unauthorized access event.

last -iF -n 50
last -iF | grep -v 'your.admin.ip' | grep -v 'reboot' | head -30

Check for Unexpected System Reboots

Unexpected reboots can indicate a rootkit that requires a reboot to take effect, a kernel panic triggered by exploitation, or an attacker rebooting into a rescue environment. The reboot pseudo-user in last output shows all system startup and shutdown events with timestamps.

last reboot -F
last shutdown -F

Security Relevance: Login Records as Forensic Evidence

The /var/log/wtmp file is a binary database maintained by the system’s login infrastructure. Because it is binary and appended to by the kernel’s utmp-writing routines, it is somewhat more resistant to casual tampering than plain-text log files — a simple text editor cannot corrupt it silently without causing parse errors. However, it is not tamper-proof: a root-level attacker can overwrite wtmp directly using tools like utmpdump in write mode, or simply delete and recreate the file, leaving an empty or truncated record. A completely empty or unusually small wtmp on an active server is itself a significant indicator of log tampering and should be treated as an incident finding. For authoritative forensics, combine last output with journalctl sshd queries and external authentication logs — cloud provider audit logs, network firewall connection logs — to cross-validate and identify discrepancies.

  • An empty wtmp file on an active server is a strong indicator of log clearing by an attacker
  • last only shows successful logins — use lastb for failed authentication attempts
  • wtmp can be tampered by a root-level attacker — always cross-reference with journalctl sshd and cloud provider audit logs
  • Sessions showing 'still logged in' for unexpected durations may indicate an active unauthorized session — verify with 'who' and 'w'
  • last output is limited by wtmp retention — rotated archives at /var/log/wtmp.1 extend the history window

Practical Examples

Build a complete access timeline for a specific user account

last -iF targetuser

Shows every login and logout event for the target account with full timestamps and IP addresses. Use this as the starting point for any account-specific investigation. Look for unusual hours, unfamiliar source IPs, and session durations that don’t match normal usage patterns.

Check for any logins that occurred during an off-hours window

last -iF | awk '{print $1, $3, $5, $6, $7}' | grep -E '(Sat|Sun|0[0-6]:[0-9][0-9])'

Filters login history for weekend sessions and sessions beginning in the 00:00-06:59 window (early hours). Unauthorized access frequently occurs during off-hours to minimize the chance of detection. Adjust the time filter to match your actual maintenance windows.

Verify wtmp file integrity and detect potential tampering

ls -la /var/log/wtmp
stat /var/log/wtmp
last | tail -1

Checks the size and modification time of wtmp. A recently modified wtmp on a server with no recent logins may indicate tampering. The ‘last | tail -1’ line should show ‘begins …’ with the date the file was first written — a recent begin date on a long-running server indicates the file was cleared or replaced.

Troubleshooting Common Issues

Problem: last shows no output or 'begins …' from only a few days ago

Solution: wtmp has been rotated or cleared. Check /var/log/wtmp.1 for the previous rotation: last -f /var/log/wtmp.1. If both are empty or missing history, the file may have been cleared by an attacker — treat this as a security incident indicator.

Problem: Source hostnames appear instead of IP addresses

Solution: Use last -i to force IP address display. Hostname resolution can be slow, inaccurate, or absent for attacker IP ranges — always use IPs for security investigations to avoid DNS-based confusion.

Problem: Sessions show 'still logged in' for users who are not active

Solution: Run who and w to check actually active sessions. ‘Still logged in’ in last output can occur if a session’s logout record was not written (e.g., due to a crash or kill -9 of the session). It can also indicate an actual active session from an unauthorized connection — investigate with ss -tnp and check for active SSH connections.

Summary

The last command provides instant access to the complete login history of a Linux server from the wtmp binary log. It is the first tool to run when investigating unauthorized access — giving you source IPs, session durations, and exact timestamps without requiring elevated privileges or additional software. Combine it with lastb for failed attempts, journalctl -u sshd for detailed SSH event data, and cloud provider audit logs for a tamper-resistant external verification layer.

  • Run last -iF username immediately when investigating any account — it gives a complete access timeline with IP and timestamps
  • An unusually small wtmp or empty last output on an active server is a log tampering indicator — treat it as a security incident
  • Always use -i flag to display IPs not hostnames, and -F for full timestamps — default output truncates both

Do You Know Who Last Logged Into Your Server?

INTRAM monitors login activity, detects geographic anomalies, and alerts on unauthorized SSH access across all managed Linux servers.

Get 24/7 Login Monitoring

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.