There are several simple perl parsers for wtmp files, like wtmp.pl by "Brocade Blue"

http://brocadeblue.blogspot.com/2012/10/perl-script-to-parse-wtmp-logs.html

Full source of wtmp.pl with minor typos fixed:

#!/usr/bin/perl
@type = (
    "Empty", "Run Lvl", "Boot", "New Time", "Old Time", "Init",
    "Login", "Normal",  "Term", "Account"
);
$recs = "";
while (<>) { 
    $recs .= $_;
}
foreach ( split( /(.{384})/s, $recs ) ) {
    next if length(type, line, $inittab, $user, $host, t2, t4, _ =~ /(.{4})(.{4})(.{32})(.{4})(.{32})(.{256})(.{4})(.{4})(.{4})(.{4})(.{4})/s;
    if ( defined $line && $line =~ /\w/ ) {  ##FILTER
        $line =~ s/\x00+//g;
        $host =~ s/\x00+//g;
        $user =~ s/\x00+//g;
        printf(
            "%s %-8s %-12s %10s %-45s \n",
            scalar( gmtime( unpack( "I4", type[ unpack( "I4", $type ) ],
            $user,   $line,   $host
        );
    }
}
printf "\n" 

The script may not work on 64-bit machines. The "384" and long line with (.{4}) should be fixed for 64-bit environment.

PS: to see really all records, disable the expression in the if marked with "##FILTER".

Answer from osgx on serverfault.com
Top answer
1 of 4
18

All three of the files that you want to read are stored in binary format. They are not plain text files and cannot be read with a normal text editor, or by using the cat command. Doing so will result in garbled output as you have noted.

Below are the functions of each of the three files:

  • The file /var/log/btmp records failed login attempts.
  • The file /var/run/utmp allows one to discover information about who is currently using the system. This file will contain information on a user's logins: on which terminals, logouts, system events and the current status of the system, system boot time (used by uptime) etc.
  • The file /var/log/wtmp provides an historical record of utmp data.

You can use the last command to read each of the files.

For example:

sudo last /var/log/btmp` (note: this command needs to be run using sudo)

johndoe@computer:~$ last -f /var/run/utmp
 johndoe   tty7                          Fri Jul 26 17:58   still logged in   
 reboot   system boot  3.5.0-37-generic Fri Jul 26 17:57 - 20:10 (1+02:13)  

johndoe@computer::~$ last -f /var/log/wtmp
 reboot   system boot  3.5.0-37-generic Fri Jul 26 17:57 - 20:16 (1+02:19)   
 johndoe   pts/2        :0               Fri Jul 26 17:52 - 17:55  (00:03)    
 johndoe   pts/5        :0               Fri Jul 26 12:00 - 17:55  (05:55)    
 johndoe   pts/0        :0.0             Fri Jul 26 07:11 - 11:58  (04:46)
 <snip>...

For more information see: Linux Display Date And Time Of Login and the man pages for the command "last".

2 of 4
2

Using Perl 5

#!/usr/bin/env perl
#
# ripped from https://www.hcidata.info/wtmp.htm

use warnings;

@type=("Empty","Run Lvl","Boot","New Time","Old Time","Init","Login","Normal","Term","Account");
$recs = "";

while (<>) {
    $recs .= $_
};

foreach (split(/(.{384})/s, $recs)) {
    next if length(type, line, $inittab, $user, $host, t2, t4, _ =~/(.{4})(.{4})(.{32})(.{4})(.{32})(.{256})(.{4})(.{4})(.{4})(.{4})(.{4})/s;
    if (defined $line && $line =~ /\w/) {
        $line =~ s/\x00+//g;
        $host =~ s/\x00+//g;
        $user =~ s/\x00+//g;
        printf("%s %-8s %-12s %10s %-45s\n",
            scalar(gmtime(unpack("I4", type[unpack("I4", $type)],
            $user,
            $line,
            $host,
        )
    };
};

Output will look something like

Tue Dec 20 08:08:25 2022 Term                       pts/0
Mon Dec 26 02:19:58 2022 Normal   root              pts/0 131.191.30.152
Mon Dec 26 17:27:51 2022 Term                       pts/0
Mon Dec 26 18:23:54 2022 Normal   root              pts/0 131.191.30.152
Mon Dec 26 20:06:19 2022 Term                       pts/0
Wed Dec 28 07:07:29 2022 Normal   root              pts/0 131.191.30.152

last is the canonical way to read wtmp files. But this perl script hints at the wtmp file format.

Ripped from here.

🌐
Codeberg
codeberg.org › hjacobs › utmp
hjacobs/utmp: Pure-Python library to decode/read utmp and wtmp files - Codeberg.org
with open('/var/log/wtmp', 'rb') as fd: buf = fd.read() for entry in utmp.read(buf): print(entry.time, entry.type, entry)
🌐
Medium
bromiley.medium.com › torvalds-tuesday-logon-history-in-the-tmp-files-83530b2acc28
Torvalds Tuesday: Logon History in the *tmp Files | by Matt B | Medium
December 14, 2016 - Linux users will also be familiar with the who command, which prints information about users currently logged into the system. While limited in data capture, who also parses /var/run/utmp to grab its output. You can also force who to parse /var/log/wtmp, obviously providing more details.
🌐
Web Hosting Talk
webhostingtalk.com › showthread.php
How to decrypt wtmp file in linux | Web Hosting Talk
April 28, 2013 - You can put the contents of wtmp logs file in some txt file using following command and it should show you in readable format: /var/log/wtmp >>wtmp.txt
🌐
LinuxQuestions.org
linuxquestions.org › questions › linux-security-4 › var-log-wtmp-72976
/var/log/wtmp
March 28, 2010 - What gets logged to wtmp and how would you read it? When I try reading it with vi i get hex entries. And wtmp.1 gives gibberish. Is there a certain
🌐
Blogger
manywaystosuccess.blogspot.com › 2014 › 04 › how-to-read-wtmp-btmp-and-utmp-files.html
many ways to success: How to read wtmp, btmp and utmp files + Linux
April 3, 2014 - #strings wtmp but this output doesn't show the output in human readable form. so we can use "last -f" command. like below :- last -f /var/log/wtmp we can also redirect this output to /tmp or desired location. and can then read this file properly. ----- ----- wtmp file carries login details, ...
🌐
Google Groups
groups.google.com › g › comp.os.linux.setup › c › 2y-jI8kQ5nA
How to read wtmp & utmp
The utmp/wtmp files are binary. Each entry is of the "struct utmp" type. Utilities like "last" or "who" read those records and parse their contents. To see the strings inside the utmp/wtmp file use % strings /var/adm/utmp or % od -c /var/adm/utmp
Find elsewhere
🌐
The Geek Diary
thegeekdiary.com › what-is-the-purpose-of-utmp-wtmp-and-btmp-files-in-linux
What is the purpose of utmp, wtmp and btmp files in Linux – The Geek Diary
# last -f /var/log/wtmp ### To open wtmp file and view its content use blow command. # last -f /var/run/utmp ### To see still logged in users view utmp file use last command.
🌐
Linux Man Pages
linux.die.net › man › 5 › wtmp
wtmp(5): login records - Linux man page
Note that the utmp struct from libc5 has changed in libc6. Because of this, binaries using the old libc5 struct will corrupt /var/run/utmp and/or /var/log/wtmp.
🌐
Apple Community
discussions.apple.com › thread › 135337
reading wtmp - Apple Community
September 21, 2005 - Another way to read the /var/log/wtmp file is with the 'who' command. who /var/log/wtmp last -f /var/log/wtmp as was mentioned previously. see utmp(5) manpage for details about the format of the file.
🌐
Sandfly Security
sandflysecurity.com › blog › using-linux-utmpdump-for-forensics-and-detecting-log-file-tampering
Using Linux utmpdump for Forensics and Detecting Log File Tampering
July 31, 2019 - The utmp, wtmp and btmp files are a binary format. In order to read them you will need a utility like utmpdump. In the most basic form, utmpdump allows us to quickly dump the logs and save them for later review as text.
🌐
Red Hat
access.redhat.com › solutions › 307303
What is the meaning of utmpdump /var/log/wtmp output ? - Red Hat Customer Portal
Need brief explanation of utmpdump /var/log/wtmp output. [8] [10695] [ ] [ ] [pts/0 ] [ ] [0.0.0.0 ] [Tue Jan 29 14:36:38 2013 EST] [8] [01141] [si ] [ ] [ ] [2.6.18-274.el5] [0.0.0.0 ] [Fri Feb 01 06:58:46 2013 EST] [2] [00000] [~~ ] [reboot ] [~ ] [2.6.18-274.el5] [0.0.0.0 ] [Fri Feb 01 06:58:46 2013 EST] [1] [20019] [~~ ] [runlevel] [~ ] [2.6.18-274.el5] [0.0.0.0 ] [Fri Feb 01 06:58:46 2013 EST] [5] [03701] [l3 ] [ ] [ ] [2.6.18-274.el5] [0.0.0.0 ] [Fri Feb 01 06:58:46 2013 EST] [8] [03701] [l3 ] [ ] [ ] [2.6.18-274.el5] [0.0.0.0 ] [Fri Feb 01 07:00:24 2013 EST]
🌐
Linux Handbook
linuxhandbook.com › utmp-wtmp-btmp
What are utmp, wtmp, and btmp Files in Linux?
November 17, 2023 - You will find the wtmp located inside the /var/log directory and here's how you can find the wtmp file using the ls command:
🌐
TREND OCEANS
trendoceans.com › home › blog › topic › tools › what is utmp,wtmp,btmp, and how to read?
What is utmp,wtmp,btmp, and how to read? - TREND OCEANS
June 13, 2022 - The last command leverages the /var/log/wtmp file to display all the previous logged in and logged out data.
🌐
Tenable
tenable.com › audits › items › CIS_Debian_Linux_7_v1.0.0_L2.audit:9fc76c7ae09694838355d879decbeab4
8.1.9 Collect Session Initiation Information - /var/log/wtmp<!-- --> | Tenable®
Add the following lines to the /etc/audit/audit.rules file. -w /var/run/utmp -p wa -k session-w /var/log/wtmp -p wa -k session-w /var/log/btmp -p wa -k session # Execute the following command to restart auditd# pkill -HUP -P 1 auditd Note- Use the last command to read /var/log/wtmp (last with no parameters) and /var/run/utmp (last -f /var/run/utmp)