How to Find Files Modified Exactly X Days Ago in Ubuntu (find -mtime)

The Precise Time Window

When auditing a Linux server, you often need to locate files that were modified within a very specific time frame. While you can easily search for files modified in the last 24 hours using a negative integer (-1), sometimes you need to find a log file that was generated exactly one week ago, while completely ignoring everything modified today or yesterday. To achieve this level of pinpoint accuracy, you must format the modification time flag correctly.

Using the find Command with an Exact -mtime

The Linux find command utilizes the -mtime (modification time) flag. By providing a precise integer without a plus or minus sign, you force the search engine to look for files modified exactly that many days ago.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /var/log/ directory and return every file that was modified exactly 7 days ago (between 168 and 192 hours ago), type the following command exactly:
  3. sudo find /var/log/ -type f -mtime 7
  4. Press Enter and provide your administrator password.

Understanding Linux Time Integers

Because you are searching the system log folder (/var/log/), prefixing the command with sudo is recommended. The crucial detail here is the omission of the mathematical operator. If you type -mtime -7, Linux searches for files modified within the last 7 days. If you type -mtime +7, it searches for files modified more than 7 days ago. By typing exactly 7, you restrict the search engine exclusively to the 24-hour block that occurred exactly one week ago, allowing you to instantly isolate historic logs without flooding your terminal with recent data.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.