How to Find Files Using Regular Expressions in Ubuntu (find -regex)

The Complex Pattern Matching Requirement

When searching an Ubuntu Linux server, the standard -name flag with simple wildcards (e.g., *.log) is often insufficient for highly complex queries. If you need to find log files that adhere to a strict, complex naming convention—for example, files that start with “error”, followed by exactly four digits representing a year, a hyphen, exactly two digits for a month, and end with either .log or .txt—basic wildcards will fail or return massive amounts of false positives. To execute searches with mathematical precision, you must instruct the engine to interpret your search query as a formal Regular Expression (Regex).

Using the find Command with -regex

The Linux find command utilizes the -regex flag to evaluate the entire file path against a strict regular expression pattern.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To recursively scan the /var/log/ directory for files matching a specific complex pattern, type the following command exactly:
  3. sudo find /var/log/ -type f -regex ".*error-[0-9]\{4\}-[0-9]\{2\}\.\(log\|txt\)"
  4. Press Enter.

Full Path Evaluation

The syntax replaces -name with -regex. Crucially, the find command’s regex engine evaluates the entire directory path, not just the base filename (which is why the pattern begins with .* to match the leading /var/log/ directories). The engine then strictly enforces the character classes ([0-9]) and quantifiers (\{4\}) to ensure the file ends with a precise four-digit year, a two-digit month, and specifically ends in either a log or txt extension. This command is an absolute necessity for security administrators extracting highly specific artifact patterns from massive, unstructured log repositories.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.