↑ ↓ select, Enter open, Esc close

Show successful SSH logins from the journal

Adjust the values, the command updates live
root@server
journalctl -u ssh --since "7 days ago" --no-pager | grep 'Accepted'

Filters the SSH service messages for successful logins. Each line shows the time, method (publickey or password), user and source IP, plus the fingerprint for key logins. Useful for checking who had access and when after a suspected incident.

Note: If rsyslog is installed as well, the same entries are in /var/log/auth.log. The journal only goes back as far as it is retained.

Also searched as

  • who logged in via ssh
  • show successful ssh logins
  • ssh login history journalctl

Related one-liners

All in SSH

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.