The Silent Observers
If you are managing an Ubuntu Linux server that allows remote SSH connections for multiple developers, you are rarely the only person using the machine. Several different users might be logged in simultaneously from different IP addresses, running background scripts, or altering configuration files. Before you perform a major system update or execute a command that requires a server reboot, it is a critical administrative best practice to check exactly who else is currently logged into the server so you do not accidentally sever their connection or corrupt their ongoing work.
Using the who Command
The Linux who command instantly audits the system’s active sessions and outputs a list of all currently connected users.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To view the list of active users, type the following command exactly:
who- Press Enter.
Understanding the Output
The output is incredibly concise. The terminal will display a simple list. The first column shows the username of the person logged in (e.g., “root” or “john”). The second column shows their terminal line (e.g., “pts/0”, indicating a remote SSH session). The third column displays the exact date and time they logged in, and the final column (often in parentheses) displays the IP address from which they are connecting, allowing you to instantly identify unauthorized or unexpected connections.