Skip to content

Glossary

lastlog

The file /var/log/lastlog: one fixed-size slot per UID holding that account's most recent login time, terminal and remote host.

/var/log/lastlog records the most recent login of each account. It is an array of struct lastlog indexed by UID: the slot for UID N sits at offset N × 292 bytes on x86_64, where each slot holds a 32-bit time, a 32-byte terminal name and a 256-byte remote host. On aarch64 the slot is 296 bytes. The lastlog command prints it using the local /etc/passwd.

Because the offset depends on the UID, a single login by a high UID (for example 100000) makes the file look very large. It is a sparse file: only a few blocks are actually used, so collect it with tar --sparse to avoid copying gigabytes of zeros.

Why it matters in investigations

Each login overwrites the slot, so lastlog only knows the latest login per account and keeps it indefinitely, long after wtmp has been rotated. More importantly, it is written independently of wtmp. A lastlog time for which wtmp has no matching session, while wtmp covers that period, is a strong sign that a wtmp record was removed or blanked. It also shows accounts that logged in once, years ago, and were never expected to log in at all.

Example

The slot for svc_backup (UID 1001) starts at byte 1001 × 292 = 292292:

dd if=lastlog bs=292 skip=1001 count=1 2>/dev/null | xxd

After the login in the site's walkthrough, that slot holds the login time, pts/1 and 203.0.113.45. Newer distributions replace the file with lastlog2, a SQLite database at /var/lib/lastlog/lastlog2.db with a Lastlog2 table whose Time column is in seconds.

  • wtmp and btmp: the full login history to compare against.
  • utmp: sessions open right now.
  • wtmpdb: the SQLite successor of wtmp.

Linux Log Parser reads both slot sizes and lastlog2. More in wtmp, btmp and lastlog forensics.