A security-focused guide to the last command — covering login history forensics, impossible travel detection, session duration anomalies, and wtmp file integrity for incident response.
What is the last command?
The last command reads from the /var/log/wtmp binary log file and displays a list of all user login and logout events, including the source IP address for remote SSH sessions, session duration, and the terminal used. It is one of the first commands executed during any SSH-related security investigation because it provides a complete chronological record of who accessed the server, from where, and for how long — without requiring any additional tooling. The last command is available on every Linux distribution and requires no elevated privileges for viewing the current user’s own sessions, though root sees all users’ login history. On busy servers, last -n 50 limits output to the 50 most recent entries for faster initial review.
Syntax
last
last username
last -n 20
last -a
last -F
last -i
last -f /var/log/wtmp.1last with no arguments lists all entries from wtmp, most recent first. -n N limits output to the last N entries. -a places the hostname at the end of the line (useful for wide output). -F shows full timestamps including seconds. -i displays IP addresses instead of hostnames. -f reads from an alternative wtmp file — useful for reading rotated archives.
Key Options and Flags
| Flag / Parameter | Description | Security Note |
|---|---|---|
username | Filter to show only login events for the specified user | Filter by a specific compromised account to build a precise access timeline |
-a | Display hostname/IP at the end of each line | — |
-F | Show full date and time including year and seconds | Required for precise incident timeline reconstruction — default output truncates timestamps |
-i | Show IP addresses instead of resolving hostnames | Preferred for security analysis — avoid relying on DNS resolution which can be spoofed or slow |
-n N | Limit output to the most recent N entries | — |
-f file | Read from an alternative wtmp file (e.g., rotated archives) | Use to extend the investigation window beyond the current wtmp if it has been rotated |
reboot | Filter to show only system reboot and shutdown events | Unexpected reboots are a security indicator — check last reboot against your maintenance schedule |
Common Use Cases
Detect Impossible Travel in SSH Login History
Impossible travel is when a user account shows successful logins from two geographically distant locations within a timeframe that makes physical travel impossible. With last -iF, you can see the source IP and precise timestamp of each login. Consecutive logins from different continents within minutes are a definitive indicator of credential compromise — either the account was used from two devices simultaneously, or the legitimate user’s credentials were stolen.
last -iF username | head -20Review All Recent Logins to Identify Unknown Source IPs
After any suspected breach, the first priority is determining if any unauthorized sessions occurred. Review all successful logins and compare source IPs against your expected list of admin IP addresses. Any unknown IP that achieved a successful login is a confirmed unauthorized access event.
last -iF -n 50
last -iF | grep -v 'your.admin.ip' | grep -v 'reboot' | head -30Check for Unexpected System Reboots
Unexpected reboots can indicate a rootkit that requires a reboot to take effect, a kernel panic triggered by exploitation, or an attacker rebooting into a rescue environment. The reboot pseudo-user in last output shows all system startup and shutdown events with timestamps.
last reboot -F
last shutdown -FSecurity Relevance: Login Records as Forensic Evidence
The /var/log/wtmp file is a binary database maintained by the system’s login infrastructure. Because it is binary and appended to by the kernel’s utmp-writing routines, it is somewhat more resistant to casual tampering than plain-text log files — a simple text editor cannot corrupt it silently without causing parse errors. However, it is not tamper-proof: a root-level attacker can overwrite wtmp directly using tools like utmpdump in write mode, or simply delete and recreate the file, leaving an empty or truncated record. A completely empty or unusually small wtmp on an active server is itself a significant indicator of log tampering and should be treated as an incident finding. For authoritative forensics, combine last output with journalctl sshd queries and external authentication logs — cloud provider audit logs, network firewall connection logs — to cross-validate and identify discrepancies.
- An empty wtmp file on an active server is a strong indicator of log clearing by an attacker
- last only shows successful logins — use lastb for failed authentication attempts
- wtmp can be tampered by a root-level attacker — always cross-reference with journalctl sshd and cloud provider audit logs
- Sessions showing 'still logged in' for unexpected durations may indicate an active unauthorized session — verify with 'who' and 'w'
- last output is limited by wtmp retention — rotated archives at /var/log/wtmp.1 extend the history window
Practical Examples
Build a complete access timeline for a specific user account
last -iF targetuserShows every login and logout event for the target account with full timestamps and IP addresses. Use this as the starting point for any account-specific investigation. Look for unusual hours, unfamiliar source IPs, and session durations that don’t match normal usage patterns.
Check for any logins that occurred during an off-hours window
last -iF | awk '{print $1, $3, $5, $6, $7}' | grep -E '(Sat|Sun|0[0-6]:[0-9][0-9])'Filters login history for weekend sessions and sessions beginning in the 00:00-06:59 window (early hours). Unauthorized access frequently occurs during off-hours to minimize the chance of detection. Adjust the time filter to match your actual maintenance windows.
Verify wtmp file integrity and detect potential tampering
ls -la /var/log/wtmp
stat /var/log/wtmp
last | tail -1Checks the size and modification time of wtmp. A recently modified wtmp on a server with no recent logins may indicate tampering. The ‘last | tail -1’ line should show ‘begins …’ with the date the file was first written — a recent begin date on a long-running server indicates the file was cleared or replaced.
Troubleshooting Common Issues
Problem: last shows no output or 'begins …' from only a few days ago
Solution: wtmp has been rotated or cleared. Check /var/log/wtmp.1 for the previous rotation: last -f /var/log/wtmp.1. If both are empty or missing history, the file may have been cleared by an attacker — treat this as a security incident indicator.
Problem: Source hostnames appear instead of IP addresses
Solution: Use last -i to force IP address display. Hostname resolution can be slow, inaccurate, or absent for attacker IP ranges — always use IPs for security investigations to avoid DNS-based confusion.
Problem: Sessions show 'still logged in' for users who are not active
Solution: Run who and w to check actually active sessions. ‘Still logged in’ in last output can occur if a session’s logout record was not written (e.g., due to a crash or kill -9 of the session). It can also indicate an actual active session from an unauthorized connection — investigate with ss -tnp and check for active SSH connections.
Summary
The last command provides instant access to the complete login history of a Linux server from the wtmp binary log. It is the first tool to run when investigating unauthorized access — giving you source IPs, session durations, and exact timestamps without requiring elevated privileges or additional software. Combine it with lastb for failed attempts, journalctl -u sshd for detailed SSH event data, and cloud provider audit logs for a tamper-resistant external verification layer.
- Run
last -iF usernameimmediately when investigating any account — it gives a complete access timeline with IP and timestamps - An unusually small wtmp or empty last output on an active server is a log tampering indicator — treat it as a security incident
- Always use
-iflag to display IPs not hostnames, and-Ffor full timestamps — default output truncates both
Related Commands
lastb to audit failed login attempts • journalctl for systemd authentication logs • grep auth.log for rapid log triage • fail2ban for SSH brute force prevention
Do You Know Who Last Logged Into Your Server?
INTRAM monitors login activity, detects geographic anomalies, and alerts on unauthorized SSH access across all managed Linux servers.
Get 24/7 Login Monitoring