{
    "mode": "man",
    "parameter": "aulast",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/aulast/8/json",
    "generated": "2026-10-04T18:07:32Z",
    "synopsis": "",
    "sections": {
        "NAME": {
            "content": "aulast - a program similar to last\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "",
            "subsections": [
                {
                    "name": "aulast [ options ]",
                    "content": ""
                }
            ]
        },
        "DESCRIPTION": {
            "content": "aulast  is  a  program that prints out a listing of the last logged in users similarly to the\nprogram last and lastb. Aulast searches back through the audit logs or the  given  audit  log\nfile  and  displays a list of all users logged in (and out) based on the range of time in the\naudit logs. Names of users and tty’s can be given, in which case aulast will show only  those\nentries matching the arguments.\n\nThe pseudo user reboot logs in each time the system is rebooted. Thus last reboot will show a\nlog of all reboots since the log file was created.\n\nThe  main  difference  that  a  user  will  notice is that aulast print events from oldest to\nnewest, while last prints records from newest to oldest. Also, the audit system is not  noti‐\nfied each time a tty or pty is allocated, so you may not see quite as many records indicating\nusers and their tty's.\n\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "--bad  Report on the bad logins.\n\n",
            "subsections": [
                {
                    "name": "--debug",
                    "content": "Print debug messages to stderr.\n\n",
                    "long": "--debug"
                },
                {
                    "name": "--extract",
                    "content": "Write  raw audit records used to create the displayed report into a file aulast.log in\nthe current working directory.\n\n",
                    "long": "--extract"
                },
                {
                    "name": "-f _",
                    "content": "Use the file instead of the audit logs for input.\n\n",
                    "flag": "-f"
                },
                {
                    "name": "--proof",
                    "content": "Print out the audit event serial numbers used to determine the preceding line  of  the\nreport.  A Serial number of 0 is a place holder and not an actual event serial number.\nThe serial numbers can be used to examine the actual audit  records  in  more  detail.\nAlso  an ausearch query is printed that will let you find the audit records associated\nwith that session.\n\n",
                    "long": "--proof"
                },
                {
                    "name": "--stdin",
                    "content": "Take audit records from stdin. The audit events must be in the raw format.\n\n\n--tty tty\nLimit the report to a specific tty's activity. The names of ttys can  be  abbreviated.\nFor example, 0 is the same as tty0.\n\n\n--user name\nLimit the report to a specific user.\n\n",
                    "long": "--stdin"
                }
            ]
        },
        "EXAMPLES": {
            "content": "To see this month's logins",
            "subsections": [
                {
                    "name": "ausearch --start this-month --raw | aulast --stdin",
                    "content": ""
                }
            ]
        },
        "SEE ALSO": {
            "content": "last(1), lastb(1), ausearch(8), aureport(8).\n\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "Steve Grubb\n\nRed Hat                                       June 2016                                    AULAST(8)",
            "subsections": []
        }
    },
    "summary": "aulast - a program similar to last",
    "flags": [
        {
            "flag": "",
            "long": "--debug",
            "arg": null,
            "description": "Print debug messages to stderr."
        },
        {
            "flag": "",
            "long": "--extract",
            "arg": null,
            "description": "Write raw audit records used to create the displayed report into a file aulast.log in the current working directory."
        },
        {
            "flag": "-f",
            "long": null,
            "arg": null,
            "description": "Use the file instead of the audit logs for input."
        },
        {
            "flag": "",
            "long": "--proof",
            "arg": null,
            "description": "Print out the audit event serial numbers used to determine the preceding line of the report. A Serial number of 0 is a place holder and not an actual event serial number. The serial numbers can be used to examine the actual audit records in more detail. Also an ausearch query is printed that will let you find the audit records associated with that session."
        },
        {
            "flag": "",
            "long": "--stdin",
            "arg": null,
            "description": "Take audit records from stdin. The audit events must be in the raw format. --tty tty Limit the report to a specific tty's activity. The names of ttys can be abbreviated. For example, 0 is the same as tty0. --user name Limit the report to a specific user."
        }
    ],
    "examples": [
        "To see this month's logins"
    ],
    "see_also": [
        {
            "name": "last",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/last/1/json"
        },
        {
            "name": "lastb",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/lastb/1/json"
        },
        {
            "name": "ausearch",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/ausearch/8/json"
        },
        {
            "name": "aureport",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/aureport/8/json"
        }
    ]
}