How to Find Files Accessed Exactly N Minutes Ago in Ubuntu (find -amin)

The Real-Time Audit

In Ubuntu Linux, tracking when a file was last opened (accessed) is just as important as tracking when it was modified. If you suspect a malicious actor is currently inside your system reading sensitive database files, or if you need to verify that a backup script successfully read a specific archive five minutes ago, you need a granular time filter. The standard -atime flag is useless here because it only measures time in blocks of 24 hours. To perform a real-time security audit, you must measure access timestamps in precise minutes.

Using the find Command with -amin

The Linux find command utilizes the -amin (accessed minutes) flag to search the filesystem based on exact, minute-by-minute read activity.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the /etc/ directory for any configuration files that were read less than 10 minutes ago, type the following command exactly:
  3. sudo find /etc/ -type f -amin -10
  4. Press Enter and provide your administrator password.

Granular Time Slicing

The syntax utilizes mathematical operators for precision. Using a minus sign (-10) finds files accessed less than 10 minutes ago. Using a plus sign (+10) finds files accessed more than 10 minutes ago. If you omit the operator and simply type -amin 10, the engine will exclusively return files that were opened exactly 10 minutes ago (a strict 60-second window). This surgical precision allows administrators to instantly cross-reference file access logs against active user sessions, making it a critical tool for real-time server diagnostics.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.