Linux lastb Command
Linux lastbThe command is used to list information about users who failed to log in to the system.
When executed alonelastbcommand, it will read the file located in/var/logdirectory, namedbtmpfile, and display all the usernames of failed logins recorded in that file.
Syntax
lastb [-adRx][-f <记录文件>][-n <显示行数>][帐号名称...][终端机编号...]
Parameter description:
options:
- -R Omit the hostname column
- -a Display the host name or IP address from which the system was logged in on the last line.
- -d Convert IP addresses to host names.
- -f<record file> Specify the record file.
- -n<number of lines> or -<number of lines> Display the number of lines in the list.
- -R Do not display the host name or IP address of the system login.
- -x Display system shutdown, reboot, and runlevel changes and other information.
username:
- username: Display login information for the specified user.
tty:
- tty Set the terminal for login; the tty name can be abbreviated,last 0andlast tty0same.
Examples
Display information about users who failed to log in:
# lastb ... zgg ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) zgg ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) zf ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) za ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) zeng ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) zf ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) zette ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) z310 ssh:notty 143.198.176.57 Thu Apr 7 11:27 - 11:27 (00:00) btmp begins Fri Apr 1 07:38:45 2022
Display 5 lines of failed login user information:
# lastb -n 5 mos ssh:notty 194.31.98.204 Thu Apr 28 16:52 - 16:52 (00:00) user ssh:notty 194.31.98.204 Thu Apr 28 16:52 - 16:52 (00:00) user ssh:notty 194.31.98.204 Thu Apr 28 16:52 - 16:52 (00:00) user ssh:notty 194.31.98.204 Thu Apr 28 16:52 - 16:52 (00:00) user ssh:notty 194.31.98.204 Thu Apr 28 16:52 - 16:52 (00:00) btmp begins Fri Apr 1 07:38:45 2022Other extensions
Linux Command Encyclopedia