lastlog(5) File Formats Manual lastlog(5)NAME
lastlog - Login logging file
DESCRIPTION
The log file /var/log/lastlog keeps track of the last successfull login of each user on the system. Not all programs logs this data and for
some this is configurable. The content of this file can be printed with the lastlog(8) command. Every entry has a fixed length, the file
is indexed by numerical UID. Each record contains the time, port and originating host that were used for the login.
The structure of the file is
struct lastlog {
#if __WORDSIZE == 64 && defined __WORDSIZE_COMPAT32
int32_t ll_time;
#else
time_t ll_time;
#endif
char ll_line[UT_LINESIZE];
char fail_host[UT_HOSTSIZE];
};
SEE ALSO faillog(5), faillog(8), lastlog(8), login.defs(5)pam_login February 2004 lastlog(5)
Check Out this Related Man Page
LASTLOG(8) System Management Commands LASTLOG(8)NAME
lastlog - reports the most recent login of all users or of a given user
SYNOPSIS
lastlog [options]
DESCRIPTION
lastlog formats and prints the contents of the last login log /var/log/lastlog file. The login-name, port, and last login time will be
printed. The default (no flags) causes lastlog entries to be printed, sorted by their order in /etc/passwd.
OPTIONS
The options which apply to the lastlog command are:
-b, --before DAYS
Print only lastlog records older than DAYS.
-C, --clear
Clear lastlog record of a user. This option can be used only together with -u (--user)).
-h, --help
Display help message and exit.
-R, --root CHROOT_DIR
Apply changes in the CHROOT_DIR directory and use the configuration files from the CHROOT_DIR directory.
-S, --set
Set lastlog record of a user to the current time. This option can be used only together with -u (--user)).
-t, --time DAYS
Print the lastlog records more recent than DAYS.
-u, --user LOGIN|RANGE
Print the lastlog record of the specified user(s).
The users can be specified by a login name, a numerical user ID, or a RANGE of users. This RANGE of users can be specified with a min
and max values (UID_MIN-UID_MAX), a max value (-UID_MAX), or a min value (UID_MIN-).
If the user has never logged in the message ** Never logged in** will be displayed instead of the port and time.
Only the entries for the current users of the system will be displayed. Other entries may exist for users that were deleted previously.
NOTE
The lastlog file is a database which contains info on the last login of each user. You should not rotate it. It is a sparse file, so its
size on the disk is usually much smaller than the one shown by "ls -l" (which can indicate a really big file if you have in passwd users
with a high UID). You can display its real size with "ls -s".
FILES
/var/log/lastlog
Database times of previous user logins.
CAVEATS
Large gaps in UID numbers will cause the lastlog program to run longer with no output to the screen (i.e. if in lastlog database there is
no entries for users with UID between 170 and 800 lastlog will appear to hang as it processes entries with UIDs 171-799).
shadow-utils 4.5 01/25/2018 LASTLOG(8)
Hello,
we are running AIX 4.3.3, has anyone experienced an issue with the lastlog file where there are duplicate entries. ie.
# mkpasswd -c
#mkpasswd -c
/etc/security/lastlog ---> /etc/security/lastlog.idx
3004-779 Duplicate key found. "userazs"
3004-778 Index operation failed.... (1 Reply)
Hello there,
I "discovered" an interesting command lastlog, but I couldn't find, until now:cool:, if it's possible to get a list of the launched process by users and root during a certain of time...
...any idea would be really appreciated!!!
Thanks in advance.
Giordano Bruno (3 Replies)
Dear Friends ,
From 'last' or 'lastlog' command , I can get the last login informations of the users . now as a system admin , If I want to delete the log information from this 'last' 'lastog' command , then is it possible to do ?
plz inform ... ... (1 Reply)
There is also "host_last_login" information in a file /etc/security/lastlog .
If I login to an appl (on AIX) via 'rexec' from my pc, I can see there pc's name or its IP:
tty_last_login = rexec
host_last_login = 10.50.38.74
I already collect login time/date/user into my own log... (1 Reply)
Hi Folks,
Is there a way to cleanup the root entries in the Linux server from the lastlog.
For AIX and SUN server, this has been done Via the fwtmp command. (1 Reply)