Skip to content

Glossary

wtmp and btmp

Binary Linux login records: /var/log/wtmp holds the history of sessions, boots and shutdowns; /var/log/btmp holds failed login attempts.

/var/log/wtmp and /var/log/btmp are the binary login records of Linux. wtmp is the history of interactive sessions, boots and shutdowns, read with last; btmp holds failed login attempts, read with lastb. Both are written directly by login, sshd and PAM, not through syslog, and logrotate typically rotates them monthly, keeping one old generation (wtmp.1, btmp.1).

Both files are sequences of fixed-size struct utmp records: 384 bytes on x86_64, where the time fields are 32-bit, and 400 bytes on aarch64, where they are 64-bit. last uses the layout of the machine it runs on, so an aarch64 wtmp read on an x86_64 workstation produces garbage or nothing. A login is a USER_PROCESS record; the logout is a DEAD_PROCESS record on the same terminal with an empty user name.

Why it matters in investigations

Being independent of syslog, wtmp confirms or contradicts auth.log and the journal. An interactive SSH session present in auth.log, the journal and audit.log but missing from wtmp, over a period wtmp covers, points to a log cleaner. Cleaners usually overwrite records with zeros so the file size stays aligned: last silently skips them, but utmpdump shows a record with type 0, no user and a 1970 date. A file size that is not a multiple of the record size, or times going backwards, are other signs. btmp is a third copy of password guessing, useful when text logs were cleaned; treat it as sensitive, since users sometimes type their password in the user name field.

Example

TZ=UTC last -F -i -x -f wtmp        # full dates, IPs, reboots and shutdowns
TZ=UTC lastb -F -i -f btmp          # failed logins
utmpdump wtmp > wtmp.txt            # every record, including blanked ones

Set TZ=UTC, otherwise last prints in the analysis host's zone. Non-interactive SSH (a remote command, scp, sftp) often leaves no wtmp record, which is benign.

  • utmp: the current sessions, same format.
  • lastlog: last login per UID, written independently.
  • wtmpdb: the SQLite replacement.

Linux Log Parser reads both layouts and flags blanked records. See wtmp, btmp and lastlog forensics.