Glossary
wtmpdb
The SQLite replacement for wtmp (wtmp.db), with one row per session, times in microseconds and the PAM service name; used by openSUSE and Debian 13.
wtmpdb is the SQLite replacement for the classic wtmp file. The 32-bit time fields of struct utmp on x86_64 overflow in January 2038, so newer distributions store login history in a database instead: /var/lib/wtmpdb/wtmp.db upstream and on openSUSE, /var/log/wtmp.db on Debian 13. It is written by the pam_wtmpdb module and read with wtmpdb last.
The data sits in one table, wtmp(ID, Type, User, Login, Logout, TTY, RemoteHost, Service). Type is 1 for BOOT_TIME, 2 for RUNLEVEL and 3 for USER_PROCESS. Login and Logout are microseconds since the epoch. Unlike wtmp, there is one row per session: the logout time is filled in when the session ends, and the Service column records the PAM service (sshd, login), which the classic format never had.
Why it matters in investigations
On hosts that switched, the old files may be absent or stale, and an investigator who only looks for /var/log/wtmp concludes there are no login records. Debian 13 removed last, lastb and lastlog and ships wtmpdb and lastlog2 as separate packages, so an upgraded host may have no login database at all; check before calling that deletion. SQLite also brings a write-ahead log: collect the wtmp.db-wal file next to the database if it exists, because recent rows may still be in it. The Service column helps separate SSH logins from console logins without cross-referencing auth.log.
Example
sqlite3 wtmp.db "SELECT User, TTY, RemoteHost, Service, datetime(Login/1000000,'unixepoch'), datetime(Logout/1000000,'unixepoch') FROM wtmp;"
wtmpdb last -F -f wtmp.db
Divide by 1,000,000 before converting, since the times are in microseconds. Its companion lastlog2 (/var/lib/lastlog/lastlog2.db) uses a Lastlog2(Name, Time, TTY, RemoteHost, Service) table with Time in seconds.
Related terms
- wtmp and btmp: the binary format it replaces.
- lastlog: replaced in turn by lastlog2.
- pam_unix: the PAM service names stored in
Service.
Linux Log Parser reads wtmp.db and lastlog2.db. See wtmp, btmp and lastlog forensics.