The Timeline Audit
When investigating a broken web application or a sudden spike in server storage usage on an Ubuntu machine, you usually know when the problem started (for example, “the server crashed sometime yesterday”). However, you might not know which configuration file was edited or which log file suddenly expanded to cause the crash. Instead of opening hundreds of files manually to check their timestamps, you can use the terminal to instantly scan the entire filesystem and generate a list of every single file that was modified within a specific window of time.
Using the find Command with -mtime
The standard Linux find command utilizes the -mtime (Modification Time) flag precisely for finding files based on when their contents were last altered.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- Determine the directory you want to search. To search the critical configuration folder, you would use
/etc/. - To find all files modified exactly within the last 2 days (48 hours), type the following command:
sudo find /etc/ -type f -mtime -2- Press Enter and provide your administrator password.
Refining the Timeline Filters
The -mtime flag counts time strictly in 24-hour blocks. You can modify the search logic by changing the mathematical prefix before the number:
- Less Than:
-mtime -2finds files modified less than 2 days ago (within the last 48 hours). - Greater Than:
-mtime +7finds files that have not been modified in over a week (older than 7 days). This is excellent for finding old backup archives to delete. - Exact:
-mtime 3finds files modified exactly between 72 and 96 hours ago.
If you need more precision than 24-hour blocks, use the -mmin flag instead, which measures time in minutes (e.g., -mmin -60 to find files modified in the last hour).