Command library / last
last
Show the login history for this host
Reads /var/log/wtmp and prints who logged in, from where, and when — including still-active sessions. Give it a username to see only that account's history, which is one of the fastest ways to check whether an account was used when it shouldn't have been.
Practice lastUsage
last [-n N] [username]
Options and flags
usernameshow only this account's login history
-nNshow only the last N entries
-aprint the hostname in the last column, for easier reading
Examples
lastThe full recent login history for every account.
last -n 10Just the 10 most recent logins — a quick glance.
last rootEvery time the root account has logged in — worth checking after any suspected compromise.
Common mistakes
last -n last -n 10
-n needs a number right after it — how many entries to show — or it has nothing to limit by.