How to Find Files Modified by Date in Ubuntu (find -mtime)

The Modification Timestamp

Every file in an Ubuntu Linux file system maintains a strict “modification time” (mtime) metadata tag. This timestamp records the exact moment the actual contents of the file were last changed or saved. When investigating a security breach or trying to locate a configuration file you edited “sometime last week,” you cannot rely on filenames. You must instruct the Linux search engine to filter the file system based exclusively on exactly when the file data was last rewritten.

Using the find Command with -mtime

The Linux find command utilizes the highly specific -mtime flag to isolate files based on how many 24-hour periods have elapsed since their contents were last altered.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /etc/ directory and return only files that have been modified within the last 7 days, type the following command exactly:
  3. sudo find /etc/ -type f -mtime -7
  4. Press Enter and provide your administrator password.

Auditing Historical Changes

The minus (-) modifier means “less than,” while a plus (+) means “greater than.” If you are trying to find massive log files that have completely stopped updating, you could run find /var/log/ -type f -mtime +30. This command will scan your server and output a list of any file whose contents have remained completely frozen and unchanged for more than an entire month, allowing you to easily identify dead services or broken logging scripts.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.