The UID Audit
In Ubuntu Linux, the operating system tracks file ownership not by the textual username (like “admin” or “john”), but by a numerical User ID (UID). When an employee leaves a company and their user account is deleted from the system, their files are not automatically destroyed; they are left orphaned, owned by a raw UID number that no longer maps to a name. To securely clean up a server and reassign or delete these orphaned files, you cannot search by username. You must explicitly query the filesystem for the raw numerical UID.
Using the find Command with -uid
The Linux find command utilizes the -uid flag to search for files based exclusively on the exact numerical identifier of the owner.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/home/directory for any files owned by UID 1005 (the standard ID for the 5th user created on the system), type the following command exactly: sudo find /home/ -uid 1005- Press Enter and provide your administrator password.
Targeting Orphaned Data
The -uid flag is the only reliable way to audit a system after account deletion. If you try to use the standard -user john command after the user “john” has been removed from /etc/passwd, the command will simply crash with an “invalid user” error. By passing the raw integer to -uid, you bypass the system’s naming abstraction entirely, allowing you to instantly locate every single abandoned document, configuration file, and cached image that belonged to the deleted user.