Investigate a user
1last # the last user connections to a server (based on /var/log/wtmp or btmp).
2ac -d # statistics of my connection time per day.
3ac -p <user> # the connection time of all users (or of a specific user).
4finger # who is connected (-l to also see mails and plans of all users).
5w # who is connected, doing what, and how much CPU they use.
6who # who is connected (-u for more info: PID, etc.).
7who am i # with which login I am connected.
8id -a # all info about the user I'm connected as (more precise than "who am i").
9logname # the login name of the current account.
Reboots & uptime
1last reboot # see all the reboots that took place.
2uptime # see how long the server has been up + the load average.
3lslogins -L # also shows whether a user shutdown/rebooted the machine.