How To Use The Find Command In Linux

5 min read

How to Use the Find Command in Linux

The find command in Linux is one of the most powerful utilities for locating files and directories based on a wide range of criteria. Which means whether you need to hunt down a misplaced configuration file, clean up temporary logs, or perform batch operations on matching items, mastering find saves time and reduces frustration. This guide walks you through the syntax, essential options, practical examples, and performance tips so you can wield the tool with confidence It's one of those things that adds up..

Real talk — this step gets skipped all the time.


Introduction

At its core, find walks a directory tree recursively, testing each entry against user‑specified expressions. When an expression evaluates to true, the file’s path is printed (or acted upon). Because the command can combine tests with logical operators (-and, -or, -not) and execute actions on matches, it serves both as a simple locator and as a foundation for complex automation scripts.

The official docs gloss over this. That's a mistake.

Key strengths:

  • Flexible criteria: name, size, type, timestamps, permissions, ownership, and more.
  • Actions: delete, exec, print0, etc., enabling safe batch processing.
  • Portability: available on virtually every Unix‑like system.

Basic Syntax

find [starting-point...] [expression]
  • starting-point – One or more directories where the search begins. If omitted, . (the current directory) is assumed.
  • expression – A series of tests, actions, and operators that determine what find does with each file it encounters.

A minimal example that lists every file under /home/user:

find /home/user

Common Options and Tests

Below are the most frequently used predicates. Combine them to narrow results precisely.

Option Description Example
-name pattern Match base name against shell‑style pattern (quotes prevent expansion). And find . -name "*.conf"
-iname pattern Case‑insensitive version of -name. Now, find . -iname "README*"
-type c Match file type: f (regular file), d (directory), l (symlink), b (block device), c (character device), p (named pipe), s (socket). find /etc -type f
-size n[cwbkMG] Match size; suffixes: c (bytes), w (2‑byte words), b (512‑byte blocks), k (kilobytes), M (megabytes), G (gigabytes). Prefix + for greater than, - for less than, no sign for exact. find /var/log -size +10M
-mtime n Match modification time in 24‑hour days. On top of that, n days ago exactly, +n more than, -n less than. So find . Worth adding: -mtime -7 (modified within last week)
-atime n Same as -mtime but for last access time. find /tmp -atime +30
-ctime n Same as -mtime but for inode change time (permission/ownership changes). In practice, find . Which means -ctime 0
-user username File owned by given user (numeric UID also works). find / -user root
-group groupname File owned by given group. In real terms, find . In real terms, -group staff
-perm mode Match exact permission bits (octal or symbolic). Use - prefix to test that at least those bits are set. Practically speaking, find . -perm -u+x (files executable by owner)
-empty Match empty regular files or directories. In practice, find /tmp -type d -empty
-prune Descend no further into matching directories (useful to exclude trees). `find / -path "/proc" -prune -o -type f -name "*.

Logical operators (implicitly -and when placed side‑by‑side):

  • -o or -or – logical OR. Even so, or-not– logical NOT. -!- -a or -and – logical AND (often omitted).
  • Parentheses \( … \) group expressions (must be escaped or quoted).

Practical Examples

1. Locate All PDF Files Larger Than 5 MB in Your Home Directory

find ~ -type f -name "*.pdf" -size +5M

2. Find Empty Directories and Remove Them Safely

find /var/tmp -type d -empty -delete

Note: -delete implies -depth, ensuring children are processed before parents.

3. Identify Files Modified in the Last 48 Hours Owned by a Specific User

find /opt/app -user alice -mtime -2 -type f

4. Search for Files Containing a Specific Pattern in Their Name, Ignoring Case, and Exclude the .git Directory

find . -type f -iname "*config*" ! -path "*/.git/*"

5. Execute a Command on Each Match (e.g., Change Permissions)

find /web -type f -name "*.html" -exec chmod 644 {} \;

Here {} is replaced by the current file path; \; terminates the -exec action Small thing, real impact..

6. Use -print0 and xargs to Handle Filenames with Spaces or Newlines

find /data -type f -name "*.bak" -print0 | xargs -0 rm -v

-print0 separates outputs with a null character; xargs -0 reads them safely.

7. Perform a Complex Condition: Files Larger Than 1 MB or Newer Than 7 Days

find . \( -size +1M -o -mtime -7 \) -type f

Parentheses group the OR condition; the outer implicit AND with -type f ensures only regular files are considered.

8. Exclude Multiple Directories (e.g., /proc, /sys, /dev) While Searching for Core Dumps

find / -type f -name "core.*" \
    \( -path "/proc/*" -o -path "/sys/*" -o -path "/dev/*" \) -prune -o -print

Each -path test is combined with -o; -prune stops descent into those trees; -o -print prints everything else that survived.


Combining find with -exec for Batch Processing

The -exec predicate lets you run any command on each match. Two forms exist:

  • -exec command {} ; – Executes command once per file.
  • -exec command {} + – Batches as many filenames as possible per invocation (more
New In

Hot Right Now

Same Kind of Thing

Similar Stories

Thank you for reading about How To Use The Find Command In Linux. We hope the information has been useful. Feel free to contact us if you have any questions. See you next time — don't forget to bookmark!
⌂ Back to Home