When a user logs in what files are updated in UNIX / Linux

One of our regular reader asks:

ADVERTISEMENTS

I’d like to discover information about who is currently using the system. When a user logs in what files are updated in UNIX / Linux?

Linux / UNIX have utmp and wtmp files to keep login records. Following three files keeps track of all logins and logouts to the system.

=> /var/run/utmp : List of current login sessions.
=> /var/log/wtmp : Database of past user logins / previous login sessions.
=> /var/log/lastlog : Last logins information about users

How do I access login records files?

These are a binary log files, and grows linearly at its end. So you cannot view records using cat or other text based utilities. The file <utmp.h> declares the structures used to record information about current users in the file. This can be accessed using C programs or other specialized utilities:

Suggested readings:

  • Man pages – ac(1), date(1), last(1), login(1), who(1), getutent(3), updwtmp(3), init(8), wtmp(5)
  • Header file /usr/include/utmp.h
🐧 Get the latest tutorials on SysAdmin, Linux/Unix, Open Source & DevOps topics via:
CategoryList of Unix and Linux commands
File Managementcat
FirewallAlpine Awall CentOS 8 OpenSUSE RHEL 8 Ubuntu 16.04 Ubuntu 18.04 Ubuntu 20.04
Network Utilitiesdig host ip nmap
OpenVPNCentOS 7 CentOS 8 Debian 10 Debian 8/9 Ubuntu 18.04 Ubuntu 20.04
Package Managerapk apt
Processes Managementbg chroot cron disown fg jobs killall kill pidof pstree pwdx time
Searchinggrep whereis which
User Informationgroups id lastcomm last lid/libuser-lid logname members users whoami who w
WireGuard VPNAlpine CentOS 8 Debian 10 Firewall Ubuntu 20.04

ADVERTISEMENTS
4 comments… add one
  • Justin Oct 2, 2007 @ 22:11

    lsof will give you a list of all files being accessed at the moment and the users that are accessing them, among other things.

  • Nikhil Mulley Oct 3, 2007 @ 19:32

    there is apparently another file which not many know of is /var/log/btmp and the related command to read it is lastb.
    lastb is same as that of last except that it shows all the bad login attempts which are recorded into /var/log/btmp, if the file is not present you would have to touch it to get started.

    Nikhil

  • 🐧 nixCraft Oct 4, 2007 @ 15:29

    Nikhil,

    Oh I just forgot about lastb., I appreciate your post.

    • Krish Mar 30, 2011 @ 17:53

      Can you pls tell me how to information on this log files

Leave a Reply

Your email address will not be published. Required fields are marked *

Use HTML <pre>...</pre>, <code>...</code> and <kbd>...</kbd> for code samples.