↑ ↓ select, Enter open, Esc close

Show recent server logins with IP address

Adjust the values, the command updates live
user@server
last -i | head -30

Reads /var/log/wtmp and shows the most recent logins with user, terminal, IP address, start time and duration. Entries with still logged in are active sessions, lines with reboot mark reboots. Useful as a quick overview of who logged in when and from where.

Note: As root, lastb shows the failed logins from /var/log/btmp. Newer distributions from Debian 13 onward switch to wtmpdb.

Also searched as

  • show last logins linux
  • who logged into my server
  • last command with ip address

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.