Show successful SSH logins from the journal
who logged in via ssh | show successful ssh logins | ssh login history journalctl | journalctl | login | auditjournalctl -u ssh --since "7 days ago" --no-pager | grep 'Accepted'Filters the SSH service messages for successful logins. Each line shows the time, method (publickey or password), user and source IP, plus the fingerprint for key logins. Useful for checking who had access and when after a suspected incident.
Note: If rsyslog is installed as well, the same entries are in /var/log/auth.log. The journal only goes back as far as it is retained.
Also searched as
- who logged in via ssh
- show successful ssh logins
- ssh login history journalctl