How to Find Files Accessed in the Last N Days in Ubuntu (find -atime)

The Access Audit

In Ubuntu Linux, every file tracks three distinct timestamps: when it was modified (mtime), when its metadata changed (ctime), and when it was last accessed or read (atime). While modified time is useful for finding recently edited files, access time is critical for security audits and storage management. If you suspect an unauthorized user read a highly sensitive text file, or if you simply want to locate old archives that haven’t been opened by anyone in over a year so you can delete them, you must instruct the Linux search engine to filter files based exclusively on their access timestamps.

Using the find Command with -atime

The Linux find command utilizes the -atime (access time) flag to isolate files based on exactly when they were last opened or read, measured in 24-hour blocks.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /var/www/html/ directory and return all files that have been read within the last 7 days, type the following command exactly:
  3. sudo find /var/www/html/ -type f -atime -7
  4. Press Enter and provide your administrator password.

Time Modifiers

The minus (-) and plus (+) modifiers are absolutely critical when using -atime. Using -7 means “accessed less than 7 days ago” (recent activity). Conversely, using +365 means “accessed more than 365 days ago.” This makes sudo find / -type f -atime +365 the ultimate command for finding massive, ancient files on your server that haven’t been looked at in over a year, making them prime candidates for deletion or archiving.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.