linux · difficulty ◆◆◆
find — locate files by criteria
Walk the filesystem and return only what matches your criteria.
`find` and `grep` are the two tools people swap on autopilot — then wonder why `grep -r` mangles their logs. find does not search text; it walks the filesystem. Get that straight and half the confusion disappears.
$ findWhat it does
find walks a directory tree and prints (or acts on) files that match a set of tests: name, type, size, modification time, permissions, and more. It is the filesystem version of grep — instead of matching text lines, it matches files.
Why it matters
find answers "where is this file?" and "which files changed recently?" in one command. Unlike ls, it searches recursively by default and can execute actions on results with -exec, making it a scripting workhorse.
Example
$ find . -name '*.log'./server.log
./build/server.log
./cache/debug.log-name does a case-sensitive glob match on the filename.
$ find /var/log -type f -mtime -2/var/log/syslog
/var/log/auth.log
/var/log/nginx/access.log-mtime -2 finds files modified in the last 2 days.
Common flags
- -name
- match filename (case-sensitive glob)
- -iname
- match filename, ignoring case
- -type
- match type: f=file, d=dir, l=symlink
- -size
- match size, e.g. +1M (larger than 1 megabyte)
- -mtime
- match modification age in days (e.g. -2, +30)
- -exec
- run a command on each result, e.g. ... -exec rm {} ;
History
Origin
find has been part of Unix since the 1970s. Its unusual expression syntax (predicates that can be combined with -and, -or, and -not) was ahead of its time and remains largely unchanged today. It is a direct ancestor of more modern search tools.
Fun fact
Modern systems often add alternatives — the newer "fd" and "ripgrep" (rg) are faster on big trees — but find is guaranteed present on every Unix-like system, which is why scripts still rely on it.
Fun facts
Pros & cons
pros
- + Universal and guaranteed present on every Unix-like system
- + Recursive by default, with powerful boolean predicate expressions
- + Can act on results (-exec) in addition to finding them
- + Expressions cover name, type, size, time, permissions, and depth
cons
- − Per-match -exec is slow on large trees
- − Expression syntax is easy to get wrong without parentheses
- − No built-in sorting or output formatting — pipe to sort or use -printf
- − Modern alternatives like fd are faster and have saner defaults
Takeaways
- 1Quote patterns so the shell does not expand them first
- 2Combine tests with parentheses and -o to build precise searches
- 3Use -mtime -7 to find everything changed in the last week
- 4For bulk actions, pipe to xargs -0 instead of -exec
- 5Try fd (a faster find) once you outgrow the syntax