How to Use the Find Command in Linux
The find command in Linux is one of the most powerful utilities for locating files and directories based on a wide range of criteria. Which means whether you need to hunt down a misplaced configuration file, clean up temporary logs, or perform batch operations on matching items, mastering find saves time and reduces frustration. This guide walks you through the syntax, essential options, practical examples, and performance tips so you can wield the tool with confidence It's one of those things that adds up..
Real talk — this step gets skipped all the time.
Introduction
At its core, find walks a directory tree recursively, testing each entry against user‑specified expressions. When an expression evaluates to true, the file’s path is printed (or acted upon). Because the command can combine tests with logical operators (-and, -or, -not) and execute actions on matches, it serves both as a simple locator and as a foundation for complex automation scripts.
The official docs gloss over this. That's a mistake.
Key strengths:
- Flexible criteria: name, size, type, timestamps, permissions, ownership, and more.
- Actions: delete, exec, print0, etc., enabling safe batch processing.
- Portability: available on virtually every Unix‑like system.
Basic Syntax
find [starting-point...] [expression]
- starting-point – One or more directories where the search begins. If omitted,
.(the current directory) is assumed. - expression – A series of tests, actions, and operators that determine what
finddoes with each file it encounters.
A minimal example that lists every file under /home/user:
find /home/user
Common Options and Tests
Below are the most frequently used predicates. Combine them to narrow results precisely.
| Option | Description | Example |
|---|---|---|
-name pattern |
Match base name against shell‑style pattern (quotes prevent expansion). And | find . -name "*.conf" |
-iname pattern |
Case‑insensitive version of -name. Now, |
find . -iname "README*" |
-type c |
Match file type: f (regular file), d (directory), l (symlink), b (block device), c (character device), p (named pipe), s (socket). |
find /etc -type f |
-size n[cwbkMG] |
Match size; suffixes: c (bytes), w (2‑byte words), b (512‑byte blocks), k (kilobytes), M (megabytes), G (gigabytes). Prefix + for greater than, - for less than, no sign for exact. |
find /var/log -size +10M |
-mtime n |
Match modification time in 24‑hour days. On top of that, n days ago exactly, +n more than, -n less than. So |
find . Worth adding: -mtime -7 (modified within last week) |
-atime n |
Same as -mtime but for last access time. |
find /tmp -atime +30 |
-ctime n |
Same as -mtime but for inode change time (permission/ownership changes). In practice, |
find . Which means -ctime 0 |
-user username |
File owned by given user (numeric UID also works). | find / -user root |
-group groupname |
File owned by given group. In real terms, | find . In real terms, -group staff |
-perm mode |
Match exact permission bits (octal or symbolic). Use - prefix to test that at least those bits are set. Practically speaking, |
find . -perm -u+x (files executable by owner) |
-empty |
Match empty regular files or directories. In practice, | find /tmp -type d -empty |
-prune |
Descend no further into matching directories (useful to exclude trees). | `find / -path "/proc" -prune -o -type f -name "*. |
Logical operators (implicitly -and when placed side‑by‑side):
-oor-or– logical OR. Even so,or-not– logical NOT. -!--aor-and– logical AND (often omitted).- Parentheses
\( … \)group expressions (must be escaped or quoted).
Practical Examples
1. Locate All PDF Files Larger Than 5 MB in Your Home Directory
find ~ -type f -name "*.pdf" -size +5M
2. Find Empty Directories and Remove Them Safely
find /var/tmp -type d -empty -delete
Note: -delete implies -depth, ensuring children are processed before parents.
3. Identify Files Modified in the Last 48 Hours Owned by a Specific User
find /opt/app -user alice -mtime -2 -type f
4. Search for Files Containing a Specific Pattern in Their Name, Ignoring Case, and Exclude the .git Directory
find . -type f -iname "*config*" ! -path "*/.git/*"
5. Execute a Command on Each Match (e.g., Change Permissions)
find /web -type f -name "*.html" -exec chmod 644 {} \;
Here {} is replaced by the current file path; \; terminates the -exec action Small thing, real impact..
6. Use -print0 and xargs to Handle Filenames with Spaces or Newlines
find /data -type f -name "*.bak" -print0 | xargs -0 rm -v
-print0 separates outputs with a null character; xargs -0 reads them safely.
7. Perform a Complex Condition: Files Larger Than 1 MB or Newer Than 7 Days
find . \( -size +1M -o -mtime -7 \) -type f
Parentheses group the OR condition; the outer implicit AND with -type f ensures only regular files are considered.
8. Exclude Multiple Directories (e.g., /proc, /sys, /dev) While Searching for Core Dumps
find / -type f -name "core.*" \
\( -path "/proc/*" -o -path "/sys/*" -o -path "/dev/*" \) -prune -o -print
Each -path test is combined with -o; -prune stops descent into those trees; -o -print prints everything else that survived.
Combining find with -exec for Batch Processing
The -exec predicate lets you run any command on each match. Two forms exist:
-exec command {} ;– Executes command once per file.-exec command {} +– Batches as many filenames as possible per invocation (more