The Micro-Timeline Search
In Ubuntu Linux, system administrators often need to hunt down files that were modified during a very specific, recent event. For example, if a server application suddenly crashed five minutes ago, you need to find exactly which configuration file or log was written to at that exact moment. Using the standard -mtime flag is useless here, because it only measures time in blocks of 24 hours. To perform a surgically precise search based on recent activity, you must measure the filesystem modification timestamps in minutes, not days.
Using the find Command with -mmin
The Linux find command utilizes the -mmin (modified minutes) flag to search for data based on incredibly tight, minute-by-minute timeframes.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/var/directory for files that were modified less than 15 minutes ago, type the following command exactly: sudo find /var/ -type f -mmin -15- Press Enter and provide your administrator password.
Targeting the Exact Minute
The syntax relies on mathematical prefixes. Using a minus sign (-15) finds files modified less than 15 minutes ago. Using a plus sign (+15) finds files modified more than 15 minutes ago. However, if you omit the prefix entirely and simply type -mmin 15, the search engine will exclusively return files that were modified exactly, precisely 15 minutes ago (down to the 60-second window). This granular level of control is absolutely critical for debugging immediate server crashes or tracking real-time malicious activity on a Linux machine.