The Storage Reclamation Audit
When an Ubuntu Linux server begins running out of disk space, blindly deleting large files is incredibly dangerous, as you might delete an active database dump or a virtual machine image currently in use. Conversely, blindly deleting old files is equally inefficient, as you might spend hours deleting thousands of tiny 2KB configuration backups that don’t actually reclaim any meaningful storage. To effectively clear a choked hard drive, you must intersect these two metrics: you must find files that are massive in size, but which have also been completely abandoned (unmodified) for months.
Using the find Command with -size and -mtime
The Linux find command allows you to chain the -size flag with the -mtime (Modification Time) flag to explicitly execute a two-dimensional storage audit.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To scan the
/var/log/directory and return only files that are larger than 500 Megabytes AND have not been modified in over 90 days, type the following command exactly: sudo find /var/log/ -type f -size +500M -mtime +90- Press Enter.
Dual Threshold Execution
The syntax utilizes the + mathematical operator on both flags to establish a dual minimum threshold. The engine first identifies every file exceeding 500MB. It then evaluates the modification timestamp of only those specific files. If the file was written to 89 days ago, it is instantly discarded from the results. The final output is a strictly curated list of massive, stale data blocks (often old application core dumps or archived log rotations). This compound command is an absolute necessity for system administrators executing surgical, high-yield storage reclamation without endangering active services.