Stop hunting for the last time a user actually logged in

User & Group Management

Stop hunting for the last time a user actually logged in

🧩 The Challenge

Dealing with audit requests for inactive accounts is a nightmare when you’re just looking at a static passwd file. You have no idea if that service account is actually being used or if it’s just dead weight waiting to be purged.

💡 The Fix

Use the lastlog command to pull a system-wide audit of the last login timestamp for every single user, which saves you from guessing who’s still alive. It’s built into almost every distro, but people always forget it exists when doing cleanup.

lastlog | grep -v "Never logged in" | sort -k 4,5,6

⚙️ Why It Works

This command pulls from the binary log maintained by PAM, letting you filter out the noise and focus on users with actual activity history. Sorting by the date fields at the end makes it way easier to spot accounts that haven’t been touched in years.

🚀 Pro-Tip: Pipe it into awk if you want to extract just the usernames for a bulk deletion script.

Linux Tips & Tricks | © ngelinux.com | 9/27/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted