How to Find Files by Access Time in Ubuntu (find -atime)

The Access Timestamp

Every file in an Ubuntu Linux file system maintains three distinct timestamps: when it was created, when its contents were last modified, and when it was last accessed (read or opened by a user or script). When managing a massive file server, you often need to find “dead” data—files that have not been looked at by a human being in several months or years. Deleting these forgotten files is the fastest way to reclaim hard drive space. To hunt them down, you must instruct the Linux search engine to filter the filesystem based specifically on the “access time” (atime) metadata.

Using the find Command with -atime

The Linux find command utilizes the -atime flag to instantly isolate files based on exactly how many 24-hour periods have passed since they were last read.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /home/user/Documents/ directory and explicitly return only files that have not been opened in more than 365 days, type the following command exactly:
  3. find /home/user/Documents/ -type f -atime +365
  4. Press Enter.

Targeting Recent Activity

The + modifier means “greater than”. You can flip this logic to audit recent security breaches. If you run sudo find /etc/ -type f -atime -2, the engine will search the core configuration directory and output a list of any file that has been accessed in the last 2 days (less than 48 hours ago). If you haven’t logged into the server recently, but critical password files appear on this list, you immediately know your server has been compromised.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.