How to Find Files Based on Access Time in Ubuntu (find -atime)

The Audit Trail

In Ubuntu Linux, the operating system meticulously records three separate timestamps for every single file: Modification Time (mtime), Change Time (ctime), and Access Time (atime). While modification time tells you when a file was last edited, access time tells you exactly when a file was simply opened and read by a user or a program. If you are auditing a server to determine if a malicious user recently viewed a sensitive database file, or if you are trying to archive old files that haven’t been opened in years, you must explicitly query the access timestamp.

Using the find Command with -atime

The Linux find command utilizes the -atime flag to search the filesystem based exclusively on when data was last read.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the /var/www/ directory for any files that have NOT been accessed (read) in more than 365 days, type the following command exactly:
  3. sudo find /var/www/ -type f -atime +365
  4. Press Enter and provide your administrator password.

Time Windows

The syntax utilizes mathematical operators (+ and -) representing increments of 24 hours. By typing +365, you are instructing the search engine to find files whose access time is strictly greater than 365 days ago (ideal for archiving abandoned data). Conversely, if you type -7, the command will find files that were accessed less than 7 days ago. If you use no operator and simply type 7, it will find files accessed exactly on the 7th day. Mastering this flag allows you to construct highly accurate timelines of user activity across your entire server.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.